Executive brief
The Remote Desktop Client, a tool used to access and control computers over a network, contains an integer overflow vulnerability that allows an attacker to crash the application and deny service to users. An attacker on the network can trigger this flaw without authentication, disrupting access to remote systems.
Technical details
The vulnerability is an integer overflow or wraparound flaw in the Remote Desktop Client's network processing logic. The vulnerability can be triggered by a malicious actor sending a specially crafted network packet without requiring authentication or user interaction. When exploited, the integer overflow causes the application to crash, resulting in a denial of service. The attack vector is network-based and does not require authentication, making it relatively easy for an attacker to reach the vulnerable code.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-09-08: disclosed