AI analysis
CVE-2026-83998 is a heap-based buffer overflow (CWE-122) in the Microsoft Remote Desktop Client, the component used to connect out to remote machines over RDP. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an unauthenticated network attacker can trigger the overflow, but only with user interaction — consistent with the flaw being exercised when a client establishes a connection and processes attacker-influenced data from the remote side. Successful exploitation yields remote code execution in the context of the client process, with high impact to confidentiality, integrity, and availability (CVSS 8.8 High). Users and organizations whose workstations run the affected Remote Desktop Client to reach RDP servers — administrators, support staff, and remote workers in particular — are in scope per Microsoft's September 2026 Patch Tuesday advisory. As of this analysis there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS is a modest 0.4%; the two actively exploited zero-days referenced in the September 2026 release headlines are not identified as this CVE.
What to do: Apply Microsoft's September 2026 security updates for the Remote Desktop Client via Windows Update, WSUS, or Intune, prioritizing administrator workstations, jump hosts, and support machines that routinely make outbound RDP connections. Until patched, restrict users to connecting only to trusted RDP servers and consider limiting outbound RDP (TCP 3389) to known hosts or gateways. Verify the exact affected version ranges in Microsoft's advisory, as they are not enumerated in the source data.
Affected
| Microsoft Remote Desktop Client | — |
Estimated exposure
mass≫1,000,000 users — the RDP client is an in-box component shipped with effectively all modern Windows desktop installations — The Remote Desktop Client is bundled by default with Windows client editions, giving it an installed base in the hundreds of millions, though only endpoints whose users actually initiate outbound RDP connections are concretely exploitable.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.