CVE-2026-69358: Remote Desktop Client Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Remote Desktop Client Remote Code Execution Vulnerability
Other sources
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Remote Desktop Client
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access and interaction does exploitation require?
The attacker must be authorized and have low-level privileges. Exploitation also requires user interaction and is performed over a network.
2
How likely is exploitation to succeed?
The attack complexity is rated high, indicating that exploitation requires conditions beyond basic network reachability.
3
What impact could successful exploitation have?
Successful exploitation could allow code execution and has high potential impact on confidentiality, integrity, and availability.