Junglewise Threat Intelligence

CVE-2026-77896: Microsoft Remote Desktop Client integer overflow

CVE-2026-77896 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

The Remote Desktop Client, a tool used to access and control computers over a network, contains an integer overflow vulnerability that allows an attacker to crash the application and deny service to users. An attacker on the network can trigger this flaw without authentication, disrupting access to remote systems.

Technical details

The vulnerability is an integer overflow or wraparound flaw in the Remote Desktop Client's network processing logic. The vulnerability can be triggered by a malicious actor sending a specially crafted network packet without requiring authentication or user interaction. When exploited, the integer overflow causes the application to crash, resulting in a denial of service. The attack vector is network-based and does not require authentication, making it relatively easy for an attacker to reach the vulnerable code.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-09-08: disclosed

References

Related threats