Executive brief
Windows Remote Desktop is a component that enables remote access to Windows systems over a network. A heap-based buffer overflow in this component could allow an attacker to execute arbitrary code remotely, potentially gaining complete control of affected systems without requiring authentication or user interaction.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Windows Remote Desktop that can be exploited over the network. The vulnerability allows an unauthorized attacker to execute code remotely without authentication. The attack vector is network-based, meaning exploitation is possible from any networked machine without requiring prior system access or user interaction. Successful exploitation could lead to remote code execution with system-level privileges.
Affected products
- Microsoft Windows Remote Desktop
Timeline
- 2026-09-08: disclosed