CVE-2026-78463
Microsoft · Published September 8, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Remote Desktop Client Remote Code Execution Vulnerability. Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Affected Products
- Remote Desktop client for Windows Desktop
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C