CVE-2026-62824: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Other sources
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26279Patch KB5120385 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23337Patch KB5120386 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9418Patch KB5120418
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62824?
The severity of CVE-2026-62824 is rated as high with a score of 8.8.
How do I fix CVE-2026-62824?
To fix CVE-2026-62824, apply the latest security updates provided by Microsoft for the affected Windows Server and Windows 10 versions.
What type of vulnerability is CVE-2026-62824?
CVE-2026-62824 is a Remote Code Execution vulnerability caused by a stack-based buffer overflow in the Remote Desktop Client.
What software is affected by CVE-2026-62824?
CVE-2026-62824 affects Microsoft Windows Server 2012 R2, Windows Server 2012, Windows Server 2016, and Windows 10.
What can an attacker do with CVE-2026-62824?
An unauthorized attacker can execute arbitrary code over a network using CVE-2026-62824.