CVE-2026-69358
massUninitialized-Memory RCE in Microsoft Remote Desktop Client
CVE-2026-69358 is a use-of-uninitialized-resource flaw (CWE-908) in Microsoft's Remote Desktop Client, the component used to initiate RDP sessions from Windows systems. Per the CVSS vector, an authorized attacker with low privileges must induce a user to establish an RDP session (user interaction is required), and exploitation carries high attack complexity, meaning success depends on favorable, non-deterministic conditions such as stale memory contents. If triggered, the uninitialized resource can be leveraged to execute code in the context of the RDP client, with high impact on the confidentiality, integrity, and availability of the connecting machine. Any environment whose users run the Microsoft Remote Desktop Client — which ships by default with Windows — to connect to less-trusted or attacker-controlled RDP servers is potentially affected. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a roughly 0.5% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update addressing CVE-2026-69358 through standard update channels and verify installed Remote Desktop Client builds against Microsoft's advisory. Until patched, restrict outbound RDP (TCP/UDP 3389) to trusted servers and caution users against connecting to untrusted RDP endpoints. Given the absence of known exploitation, public PoCs, or KEV listing, routine patch-cycle handling is reasonable.
| Microsoft Remote Desktop Client (Windows RDP client component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
- Weakness
- CWE-908
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.