ZeroHour

CVE-2026-68828

mass

Heap Buffer Overflow in Microsoft Remote Desktop Client Enables Network RCE

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
AI analysis

Microsoft's Remote Desktop Client contains a heap-based buffer overflow (CWE-122) that allows an unauthenticated attacker to execute code over a network. Given the CVSS vector's user-interaction requirement (UI:R), the flaw is most plausibly triggered when a user uses the client to connect to a malicious or attacker-controlled RDP server, causing the client to process attacker-controlled data. Successful exploitation would let the attacker run code in the context of the logged-on user, with high impact on confidentiality, integrity, and availability. Anyone using the affected Microsoft Remote Desktop Client — which ships by default on Windows endpoints — is potentially exposed, though only connections to untrusted servers present a realistic attack path. There is currently no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a ~0.4% probability of exploitation in the next 30 days, so no active exploitation is known.

What to do: Check Microsoft's advisory for the exact affected client versions and apply the patched Remote Desktop Client via Windows Update (or the Microsoft Update Catalog) as soon as it is available. Until patched, instruct users to connect only to trusted RDP servers and warn them about lures to connect to attacker-controlled hosts, since user interaction is required. On endpoints that do not need outbound RDP, consider blocking or restricting use of the Remote Desktop client to reduce attack surface.

Affected
Microsoft Remote Desktop Client
Estimated exposure
masshundreds of millions of Windows endpoints include the Remote Desktop client, though only hosts making outbound RDP connections to untrusted servers are… — The Microsoft Remote Desktop client is bundled by default with Windows desktops and server editions, so the potential installed base is on the order of the global Windows fleet (~1.4 billion devices), per vendor deployment patterns; actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.