Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42909
7.5HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-42909?
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Affected Version(s)
Remote Desktop client for Windows Desktop 1.2.0.0 < 1.2.7214.0
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8880