CVE-2026-80077: Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Other sources
Remote Desktop Client Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.7279.0
Event History
Frequently Asked Questions
What does an attacker need to do to exploit this vulnerability?
The attacker can target the vulnerable Remote Desktop Client over a network without prior authorization. Exploitation requires user interaction, as indicated by the UI:R vector.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution on the affected Windows desktop system. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
Which product is identified as affected?
The affected software listed is Microsoft Remote Desktop client for Windows Desktop.