Description
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Update
AI Analysis

Impact

A heap‑based buffer overflow in Microsoft’s Remote Desktop Client permits an attacker to execute arbitrary code on any Windows desktop running the vulnerable client. The flaw is triggered when the client processes data received over a network connection. Successful exploitation would give the attacker full control of the host environment, compromising all user processes and data.

Affected Systems

The problem exists in the Remote Desktop Client for Windows Desktop distributed by Microsoft. No specific version was disclosed in the advisory, so any installation of this client that has not been updated to the latest release may be vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % shows that the likelihood of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog, and no large‑scale attacks have been reported. An attacker only needs to deliver crafted data over the network; no user credential is required. Successful delivery leads to remote code execution on the target host.

Generated by OpenCVE AI on September 9, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft update for Remote Desktop Client via Windows Update or the Microsoft Update Catalog
  • Disable Remote Desktop or limit its usage if it is not required in the environment
  • Configure the local firewall or perimeter firewall to block or restrict inbound RDP traffic to trusted networks

Generated by OpenCVE AI on September 9, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft remote Desktop Client
CPEs cpe:2.3:a:microsoft:remote_desktop_client:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft remote Desktop Client

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Title Remote Desktop Client Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft remote Desktop
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:remote_desktop:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft
Microsoft remote Desktop
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Remote Desktop Remote Desktop Client
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:46.613Z

Reserved: 2026-08-25T18:37:59.828Z

Link: CVE-2026-80074

cve-icon Vulnrichment

Updated: 2026-09-09T10:00:11.328Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:49.313

Modified: 2026-09-22T13:29:06.113

Link: CVE-2026-80074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T02:15:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow