CVE-2026-78463: Remote Desktop Client Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Other sources
Remote Desktop Client Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Remote Desktop Client
Microsoft Remote Desktop client for Windows Desktop<1.2.7279.0
1.2.7279.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.7279.0
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this vulnerability?
The vulnerability is remotely reachable over a network and requires no attacker privileges. Exploitation requires user interaction.
2
What is the potential impact if exploitation succeeds?
An attacker could execute code through the Remote Desktop Client. The listed impact includes high confidentiality, integrity, and availability consequences.
3
Is exploitation known to be occurring?
The provided data lists exploit code maturity as unknown; it does not confirm known exploitation.