ZeroHour

CVE-2026-83998

mass

Heap Buffer Overflow RCE in Microsoft Remote Desktop Client

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-83998 is a heap-based buffer overflow (CWE-122) in the Microsoft Remote Desktop Client, the component used to connect out to remote machines over RDP. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an unauthenticated network attacker can trigger the overflow, but only with user interaction — consistent with the flaw being exercised when a client establishes a connection and processes attacker-influenced data from the remote side. Successful exploitation yields remote code execution in the context of the client process, with high impact to confidentiality, integrity, and availability (CVSS 8.8 High). Users and organizations whose workstations run the affected Remote Desktop Client to reach RDP servers — administrators, support staff, and remote workers in particular — are in scope per Microsoft's September 2026 Patch Tuesday advisory. As of this analysis there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS is a modest 0.4%; the two actively exploited zero-days referenced in the September 2026 release headlines are not identified as this CVE.

What to do: Apply Microsoft's September 2026 security updates for the Remote Desktop Client via Windows Update, WSUS, or Intune, prioritizing administrator workstations, jump hosts, and support machines that routinely make outbound RDP connections. Until patched, restrict users to connecting only to trusted RDP servers and consider limiting outbound RDP (TCP 3389) to known hosts or gateways. Verify the exact affected version ranges in Microsoft's advisory, as they are not enumerated in the source data.

Affected
Microsoft Remote Desktop Client
Estimated exposure
mass≫1,000,000 users — the RDP client is an in-box component shipped with effectively all modern Windows desktop installations — The Remote Desktop Client is bundled by default with Windows client editions, giving it an installed base in the hundreds of millions, though only endpoints whose users actually initiate outbound RDP connections are concretely exploitable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs