Microsoft Remote Desktop Client Heap-Based Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the Remote Desktop Client for Windows Desktop, as well as in various Windows 11 and Windows Server 2022 versions. This vulnerability allows an unauthorized attacker to execute code remotely over a network. The issue arises from a race condition that can be exploited when a victim connects to an attacking server using the vulnerable Remote Desktop Client.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Reproduction

To reproduce this vulnerability, an attacker must have control of a Remote Desktop Server and exploit a race condition when a victim connects to the server using the vulnerable Remote Desktop Client. This will trigger the buffer overflow, allowing the attacker to execute arbitrary code on the victim's machine.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Security update KB5095051 is available for Windows 11 versions 26H1, 24H2, 23H2, and 25H2, as well as for Windows Server 2025 and Windows Server 2022 (Server Core installation).

Added: Jun 9, 2026, 7:46 PM
Updated: Jun 9, 2026, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.5
remediation
0.0
relevance
9.4
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.