CVE-2026-68828
massHeap Buffer Overflow in Microsoft Remote Desktop Client Enables Network RCE
Microsoft's Remote Desktop Client contains a heap-based buffer overflow (CWE-122) that allows an unauthenticated attacker to execute code over a network. Given the CVSS vector's user-interaction requirement (UI:R), the flaw is most plausibly triggered when a user uses the client to connect to a malicious or attacker-controlled RDP server, causing the client to process attacker-controlled data. Successful exploitation would let the attacker run code in the context of the logged-on user, with high impact on confidentiality, integrity, and availability. Anyone using the affected Microsoft Remote Desktop Client — which ships by default on Windows endpoints — is potentially exposed, though only connections to untrusted servers present a realistic attack path. There is currently no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a ~0.4% probability of exploitation in the next 30 days, so no active exploitation is known.
What to do: Check Microsoft's advisory for the exact affected client versions and apply the patched Remote Desktop Client via Windows Update (or the Microsoft Update Catalog) as soon as it is available. Until patched, instruct users to connect only to trusted RDP servers and warn them about lures to connect to attacker-controlled hosts, since user interaction is required. On endpoints that do not need outbound RDP, consider blocking or restricting use of the Remote Desktop client to reduce attack surface.
| Microsoft Remote Desktop Client | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.