Description
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow that allows an attacker without local privileges to overflow a buffer in the Remote Desktop Client and execute arbitrary code. The resulting compromise can give the attacker full control of the target machine, impacting confidentiality, integrity, and availability. The vulnerability is classified as CWE-122.

Affected Systems

Affects Microsoft Remote Desktop client for Windows desktop. No specific product versions are listed in the CNA data, so any installation of the Windows Remote Desktop client is potentially vulnerable until a patch is applied.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is considered high criticality. EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is likely over the network, requiring the client to connect to a Remote Desktop server; an attacker may trigger the overflow by sending specially crafted traffic between client and server. Until a patch is installed, the system remains at risk of exploitation.

Generated by OpenCVE AI on September 9, 2026 at 21:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft security update for Remote Desktop Client (CVE-2026-80077) from Microsoft Update or the official update guide.
  • Disable Remote Desktop on systems that do not require it, or limit connectivity to trusted IP addresses using firewall rules or network segmentation.
  • Perform regular vulnerability scanning to ensure the patch is applied and monitor for any unusual Remote Desktop traffic or attempts to exploit the overflow.

Generated by OpenCVE AI on September 9, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft remote Desktop Client
CPEs cpe:2.3:a:microsoft:remote_desktop_client:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft remote Desktop Client

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Title Remote Desktop Client Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft remote Desktop
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:remote_desktop:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft
Microsoft remote Desktop
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Remote Desktop Remote Desktop Client
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:47.081Z

Reserved: 2026-08-25T18:37:59.828Z

Link: CVE-2026-80077

cve-icon Vulnrichment

Updated: 2026-09-09T10:00:09.298Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:49.860

Modified: 2026-09-22T13:20:12.967

Link: CVE-2026-80077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:30:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow