Description
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-07-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in the Remote Desktop Client that can be triggered by an attacker who initiates a connection. The flaw allows the execution of arbitrary code on the target system with the privileges of the Remote Desktop Service. The vulnerability is identified by CWE-122 and represents a critical security flaw that could compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical level of severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely but not impossible. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the most probable attack vector is a remote RDP session initiated by an unauthenticated attacker over the network, implying that exposure to the internet increases risk.

Generated by OpenCVE AI on July 31, 2026 at 09:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows 11 or Windows Server 2025 updates that contain the fix for CVE-2026-54990.
  • Enable Network Level Authentication for Remote Desktop to require authentication before a session is established.
  • Restr VPN to reduce exposure to unauthenticated users.

Generated by OpenCVE AI on July 31, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Title Remote Desktop Client Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:08.390Z

Reserved: 2026-06-16T14:10:05.868Z

Link: CVE-2026-54990

cve-icon Vulnrichment

Updated: 2026-07-15T11:14:44.241Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:45:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow