CVE-2026-78463
massCode Injection RCE in Microsoft Remote Desktop Client
Microsoft's Remote Desktop Client contains a code injection flaw (CWE-94, improper control of generation of code) that allows an unauthenticated attacker to execute arbitrary code over a network. The CVSS vector requires user interaction (UI:R), meaning exploitation depends on user action — most plausibly when the Remote Desktop Client connects to or processes data from an attacker-controlled endpoint. Successful exploitation results in arbitrary code execution with high impact on confidentiality, integrity, and availability on the affected host, running in the context of the connecting user (scope unchanged). Any environment whose users employ the Windows Remote Desktop Client to connect to untrusted servers is potentially affected. There is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.9% (57th percentile).
What to do: Track Microsoft's advisory for CVE-2026-78463 and apply the published fix for the Remote Desktop Client through Windows Update as soon as it is available. Until patched, restrict RDP client connections to trusted, known servers and avoid connecting to untrusted or attacker-controlled RDP endpoints. Inventory systems where the Remote Desktop Client is used for outbound connections to third parties, as those are the primary exposure surface.
| Microsoft Remote Desktop Client | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.