ZeroHour

CVE-2026-78463

mass

Code Injection RCE in Microsoft Remote Desktop Client

CVSS 3.1
8.8 high
EPSS
<1%p57
Published
()
Modified
AI analysis

Microsoft's Remote Desktop Client contains a code injection flaw (CWE-94, improper control of generation of code) that allows an unauthenticated attacker to execute arbitrary code over a network. The CVSS vector requires user interaction (UI:R), meaning exploitation depends on user action — most plausibly when the Remote Desktop Client connects to or processes data from an attacker-controlled endpoint. Successful exploitation results in arbitrary code execution with high impact on confidentiality, integrity, and availability on the affected host, running in the context of the connecting user (scope unchanged). Any environment whose users employ the Windows Remote Desktop Client to connect to untrusted servers is potentially affected. There is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.9% (57th percentile).

What to do: Track Microsoft's advisory for CVE-2026-78463 and apply the published fix for the Remote Desktop Client through Windows Update as soon as it is available. Until patched, restrict RDP client connections to trusted, known servers and avoid connecting to untrusted or attacker-controlled RDP endpoints. Inventory systems where the Remote Desktop Client is used for outbound connections to third parties, as those are the primary exposure surface.

Affected
Microsoft Remote Desktop Client
Estimated exposure
mass≈1 billion+ Windows endpoints ship the Remote Desktop Client (bundled with modern Windows desktop and server installs) — The Remote Desktop Client is included by default with essentially all supported Windows desktop and server installations, and public OS market-share estimates put the Windows installed base well above 1 billion devices; practically, only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.