CVE-2026-80074
massHeap Buffer Overflow in Microsoft Remote Desktop Client Allows Remote Code Execution
CVE-2026-80074 is a heap-based buffer overflow (CWE-122) in the Microsoft Remote Desktop Client that can be triggered over a network by an unauthorized attacker. The CVSS vector requires user interaction (UI:R) but no privileges (PR:N), consistent with a scenario in which a user is induced to connect to an attacker-controlled or malicious RDP server, whose network responses overflow a heap buffer in the client. Successful exploitation yields remote code execution in the context of the client user, with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Any deployment running the affected Microsoft Remote Desktop Client is exposed; the available data does not specify which versions or client variants are affected, so organizations should rely on Microsoft's advisory for exact scoping. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept is available, and EPSS estimates only a 0.6% probability of exploitation within the next 30 days (47th percentile).
What to do: Inventory endpoints with the Microsoft Remote Desktop Client and apply Microsoft's security update for CVE-2026-80074 as soon as it is released, since affected and fixed versions are not specified in the available data. In the meantime, restrict outbound RDP connections to trusted servers and caution users about unsolicited remote-session invitations, because triggering the flaw requires user interaction. No public PoC or in-the-wild exploitation is known, so standard patch-cycle handling is reasonable unless Microsoft or CISA raises the severity.
| Microsoft Remote Desktop Client | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.