Heap-based Buffer Overflow Vulnerability in Microsoft Remote Desktop Client
CVE-2026-42985

8.8HIGH

What is CVE-2026-42985?

A heap-based buffer overflow vulnerability in Microsoft’s Remote Desktop Client enables an unauthorized attacker to execute arbitrary code over a network. This flaw can be exploited by sending specially crafted requests to the client, which may lead to a complete compromise of the system. Users are encouraged to review official patches and updates to mitigate this risk.

Affected Version(s)

Remote Desktop client for Windows Desktop 1.2.0.0 < 1.2.7214.0

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8880

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.