CVE-2026-62824: Remote Desktop Client Remote Code Execution Vulnerability
Published Aug 11, 2026
·Updated
Remote Desktop Client Remote Code Execution Vulnerability
Other sources
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
13 affected componentsFixes available
Microsoft Windows Server 2016<10.0.14393.9418
10.0.14393.9418
Microsoft Windows 10=1607
10.0.14393.9418
Microsoft Windows 10=1607
10.0.14393.9418
Microsoft Windows Server 2016<10.0.14393.9418
10.0.14393.9418
Microsoft Windows Server 2012 R2<6.3.9600.23338
6.3.9600.23338
Microsoft Windows Server 2012<6.2.9200.26280
6.2.9200.26280
Microsoft Windows Server 2012<6.2.9200.26280
6.2.9200.26280
Microsoft Windows Server 2012 R2<6.3.9600.23338
6.3.9600.23338
Microsoft Windows 10 1607<10.0.14393.9418
Microsoft Windows 10 1607<10.0.14393.9418
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016<10.0.14393.9418
Remediation
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62824?
The severity of CVE-2026-62824 is rated as high with a score of 8.8.
2
How do I fix CVE-2026-62824?
To fix CVE-2026-62824, apply the latest security updates provided by Microsoft for the affected Windows Server and Windows 10 versions.
3
What type of vulnerability is CVE-2026-62824?
CVE-2026-62824 is a Remote Code Execution vulnerability caused by a stack-based buffer overflow in the Remote Desktop Client.
4
What software is affected by CVE-2026-62824?
CVE-2026-62824 affects Microsoft Windows Server 2012 R2, Windows Server 2012, Windows Server 2016, and Windows 10.
5
What can an attacker do with CVE-2026-62824?
An unauthorized attacker can execute arbitrary code over a network using CVE-2026-62824.