ZeroHour

CVE-2026-69358

mass

Uninitialized-Memory RCE in Microsoft Remote Desktop Client

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69358 is a use-of-uninitialized-resource flaw (CWE-908) in Microsoft's Remote Desktop Client, the component used to initiate RDP sessions from Windows systems. Per the CVSS vector, an authorized attacker with low privileges must induce a user to establish an RDP session (user interaction is required), and exploitation carries high attack complexity, meaning success depends on favorable, non-deterministic conditions such as stale memory contents. If triggered, the uninitialized resource can be leveraged to execute code in the context of the RDP client, with high impact on the confidentiality, integrity, and availability of the connecting machine. Any environment whose users run the Microsoft Remote Desktop Client — which ships by default with Windows — to connect to less-trusted or attacker-controlled RDP servers is potentially affected. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a roughly 0.5% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-69358 through standard update channels and verify installed Remote Desktop Client builds against Microsoft's advisory. Until patched, restrict outbound RDP (TCP/UDP 3389) to trusted servers and caution users against connecting to untrusted RDP endpoints. Given the absence of known exploitation, public PoCs, or KEV listing, routine patch-cycle handling is reasonable.

Affected
Microsoft Remote Desktop Client (Windows RDP client component)
Estimated exposure
mass~1 billion Windows installations include the client; realistically reachable population is the subset of users who initiate RDP connections to untrusted or… — The Remote Desktop Client is included by default with essentially every supported Windows client and server installation, giving an installed base on the order of hundreds of millions to over a billion devices, though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.