Junglewise Threat Intelligence

CVE-2026-80074: Remote Desktop Client heap-based buffer overflow

CVE-2026-80074 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft's Remote Desktop Client is a tool used to connect to and control computers remotely over a network. A heap buffer overflow vulnerability allows an attacker to execute malicious code on a victim's machine without authorization, potentially compromising sensitive data, installing malware, or taking over the system entirely.

Technical details

A heap-based buffer overflow exists in the Remote Desktop Client that permits remote code execution. The vulnerability is reachable over the network without requiring prior authentication, allowing an unauthenticated attacker to send specially crafted network packets to trigger the overflow and execute arbitrary code with the privileges of the Remote Desktop Client process. The exact vulnerable component and root cause are not specified in the available advisory data, but the network vector and lack of authentication requirement indicate high exploitability.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-09-08: disclosed

References

Related threats