CVE-2026-80077
massUnauthenticated RCE via Heap Buffer Overflow in Microsoft Remote Desktop Client
CVE-2026-80077 is a heap-based buffer overflow (CWE-122) in Microsoft's Remote Desktop Client that Microsoft rates as exploitable over a network by an unauthorized attacker, with a CVSS 3.1 score of 8.8 (High). The CVSS vector indicates user interaction is required (UI:R), consistent with the flaw being triggered when a user's RDP client connects to an attacker-controlled endpoint and processes crafted response data, rather than via a purely unattended network vector. Successful exploitation would allow the attacker to execute code in the context of the connecting user, with high impact on confidentiality, integrity, and availability. Any system running the affected Remote Desktop Client is exposed; the available data does not enumerate specific affected builds or operating system versions, so defenders should consult Microsoft's advisory for the affected version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.6% probability of exploitation within 30 days, so no active exploitation is currently known.
What to do: Patch via Microsoft's Windows Update channel once the fix for CVE-2026-80077 is released, and verify installed client builds against the version ranges in Microsoft's advisory since the data here does not list them. Until patched, instruct users not to connect to untrusted or unverified RDP endpoints, and monitor Microsoft's advisory and KEV/EPSS for signs of active exploitation.
| Microsoft Remote Desktop Client | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.