Executive brief
Microsoft Remote Desktop Client is a utility that allows users to connect to and control computers over a network. A code injection vulnerability in this client allows attackers to execute arbitrary code on affected systems over the network without authentication, potentially giving them full control of the compromised computer.
Technical details
A code injection vulnerability exists in Microsoft Remote Desktop Client due to improper control of code generation. The vulnerability allows an unauthenticated attacker on the network to inject and execute arbitrary code on a system running the affected Remote Desktop Client. This is a network-based attack requiring no user interaction or prior authentication. Successful exploitation grants the attacker the ability to execute code with the privileges of the user running the client. A patch is expected from Microsoft via their Security Response Center.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-09-08: disclosed