Executive brief
The Remote Desktop Client is a Microsoft application used to connect to and control computers remotely over a network. A heap-based buffer overflow vulnerability allows an attacker to send specially crafted network packets that cause the application to crash or execute malicious code with the privileges of the user running the client.
Technical details
A heap-based buffer overflow exists in the Microsoft Remote Desktop Client's network packet processing logic. The vulnerability is triggered when a remote, unauthenticated attacker sends a specially crafted RDP protocol packet over the network to the client. No user interaction or authentication is required to trigger the overflow. Successful exploitation allows arbitrary code execution in the context of the logged-in user. The attack vector is network-based, meaning the attacker can target vulnerable clients from any network location.
Affected products
- Microsoft Remote Desktop Client <UNKNOWN>
Timeline
- 2026-09-08: disclosed