Jun 2026: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42913 Published on June 9, 2026

Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Types

What is a Race Condition Vulnerability?

The program contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

CVE-2026-42913 has been classified to as a Race Condition vulnerability or weakness.

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2026-42913 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2026-42913

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 
 
 

Affected Versions

Microsoft Remote Desktop client for Windows Desktop: Microsoft Windows 11 version 23H2: Microsoft Windows 11 Version 23H2: Microsoft Windows 11 Version 24H2: Microsoft Windows 11 Version 25H2: Microsoft Windows 11 version 26H1: Microsoft Windows Server 2022: Microsoft Windows Server 2025: Microsoft Windows Server 2025 (Server Core installation):