Junglewise Threat Intelligence

CVE-2026-69358: Microsoft Remote Desktop Client code execution via uninitialized resource

CVE-2026-69358 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

Microsoft Remote Desktop Client is a widely-deployed application used by organizations to access and manage remote computers. An authorized attacker can exploit an uninitialized resource vulnerability in this client to execute arbitrary code on a user's local machine over the network, potentially leading to unauthorized access, data theft, or lateral movement within an organization's IT environment.

Technical details

This vulnerability exploits a use of uninitialized resource flaw in the Remote Desktop Client. An authorized attacker with network access can craft a malicious RDP connection or response to trigger the uninitialized resource condition, allowing arbitrary code execution in the context of the user running the client. The attack requires the target user to be connected to or accepting connections from the attacker's malicious RDP server. While the vulnerability requires authorization/connectivity to a Remote Desktop service, successful exploitation grants code execution on the client system.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: CVE-2026-69358

References

Related threats