CyberICT

CVE-2026-78463

Microsoft · Published September 8, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Remote Desktop Client Remote Code Execution Vulnerability. Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Affected Products

  • Remote Desktop client for Windows Desktop

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C