ZeroHour

CVE-2026-80077

mass

Unauthenticated RCE via Heap Buffer Overflow in Microsoft Remote Desktop Client

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
AI analysis

CVE-2026-80077 is a heap-based buffer overflow (CWE-122) in Microsoft's Remote Desktop Client that Microsoft rates as exploitable over a network by an unauthorized attacker, with a CVSS 3.1 score of 8.8 (High). The CVSS vector indicates user interaction is required (UI:R), consistent with the flaw being triggered when a user's RDP client connects to an attacker-controlled endpoint and processes crafted response data, rather than via a purely unattended network vector. Successful exploitation would allow the attacker to execute code in the context of the connecting user, with high impact on confidentiality, integrity, and availability. Any system running the affected Remote Desktop Client is exposed; the available data does not enumerate specific affected builds or operating system versions, so defenders should consult Microsoft's advisory for the affected version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.6% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Patch via Microsoft's Windows Update channel once the fix for CVE-2026-80077 is released, and verify installed client builds against the version ranges in Microsoft's advisory since the data here does not list them. Until patched, instruct users not to connect to untrusted or unverified RDP endpoints, and monitor Microsoft's advisory and KEV/EPSS for signs of active exploitation.

Affected
Microsoft Remote Desktop Client
Estimated exposure
mass≈ hundreds of millions of Windows endpoints ship the affected client, though exploitation additionally requires a user to connect to a malicious RDP server — The Remote Desktop Client is a built-in component of Microsoft Windows desktop installations, which run on hundreds of millions of devices worldwide, making the potential install base extremely large even though only users who connect to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.