CVE-2026-80074: Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Other sources
Remote Desktop Client Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.7279.0
Event History
Frequently Asked Questions
What access and user involvement does exploitation require?
The CVSS vector indicates network reachability, low attack complexity, and no attacker privileges are required. It also indicates that user interaction is required.
What security impact is indicated if exploitation succeeds?
The CVSS vector rates confidentiality, integrity, and availability impact as high. This means a successful exploit could affect all three security objectives.
Is remediation available, and how mature is public exploitation?
The temporal CVSS metrics indicate that an official fix is available. Exploit code maturity is listed as unproven.