Executive brief
Microsoft Remote Desktop Client is a widely-deployed application used by organizations to access and manage remote computers. An authorized attacker can exploit an uninitialized resource vulnerability in this client to execute arbitrary code on a user's local machine over the network, potentially leading to unauthorized access, data theft, or lateral movement within an organization's IT environment.
Technical details
This vulnerability exploits a use of uninitialized resource flaw in the Remote Desktop Client. An authorized attacker with network access can craft a malicious RDP connection or response to trigger the uninitialized resource condition, allowing arbitrary code execution in the context of the user running the client. The attack requires the target user to be connected to or accepting connections from the attacker's malicious RDP server. While the vulnerability requires authorization/connectivity to a Remote Desktop service, successful exploitation grants code execution on the client system.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: CVE-2026-69358