Heap-Based Buffer Overflow in Microsoft Remote Desktop Client
CVE-2026-44799

7.5HIGH

What is CVE-2026-44799?

A heap-based buffer overflow vulnerability exists in the Microsoft Remote Desktop Client, which could allow an unauthorized attacker to execute arbitrary code via crafted network packets. Exploitation of this vulnerability may enable remote execution of commands on the affected client, potentially compromising sensitive data and system integrity. Users are advised to apply available security patches as recommended by Microsoft.

Affected Version(s)

Remote Desktop client for Windows Desktop 1.2.0.0 < 1.2.7214.0

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8880

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.