CVE-2026-42909
published 2026-06-09CVE-2026-42909: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
PriorityP349high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.32%
23.9th percentile
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | remote_desktop_client | < 1.2.7214 | 1.2.7214 |
| microsoft | remote_desktop_client_for_windows_desktop | >= 1.2.0.0 < 1.2.7214.0 | 1.2.7214.0 |
| microsoft | windows_10_1607 | < 10.0.14393.9234 | 10.0.14393.9234 |
| microsoft | windows_10_1809 | < 10.0.17763.8880 | 10.0.17763.8880 |
| microsoft | windows_10_21h2 | < 10.0.19044.7417 | 10.0.19044.7417 |
| microsoft | windows_10_22h2 | < 10.0.19045.7417 | 10.0.19045.7417 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9234 | 10.0.14393.9234 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.8880 | 10.0.17763.8880 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7417 | 10.0.19044.7417 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7417 | 10.0.19045.7417 |
| microsoft | windows_11_23h2 | < 10.0.22631.7219 | 10.0.22631.7219 |
| microsoft | windows_11_24h2 | < 10.0.26100.8655 | 10.0.26100.8655 |
| microsoft | windows_11_25h2 | < 10.0.26200.8655 | 10.0.26200.8655 |
| microsoft | windows_11_26h1 | < 10.0.28000.2269 | 10.0.28000.2269 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7219 | 10.0.22631.7219 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.8655 | 10.0.26100.8655 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.8655 | 10.0.26200.8655 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2269 | 10.0.28000.2269 |
| microsoft | windows_app | < 2.0.1193.0 | 2.0.1193.0 |
| microsoft | windows_app_client_for_windows_desktop | >= 1.00 < 2.0.1193.0 | 2.0.1193.0 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.26132 | 6.2.9200.26132 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.23228 | 6.3.9600.23228 |
| microsoft | windows_server_2016 | < 10.0.14393.9234 | 10.0.14393.9234 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9234 | 10.0.14393.9234 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2025 Remote Desktop Client race condition
vuldb·2026-06-15·CVSS 7.5
CVE-2026-42909 [HIGH] Microsoft Windows up to Server 2025 Remote Desktop Client race condition
A vulnerability categorized as critical has been discovered in Microsoft Windows. This affects an unknown function of the component Remote Desktop Client. Such manipulation leads to race condition.
This vulnerability is listed as CVE-2026-42909. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ghsa_unreviewed·2026-06-09
CVE-2026-42909 [HIGH] CWE-362 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
blogs_tenable·2026-06-09·CVSS 9.1
CVE-2026-49160 [CRITICAL] Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
## Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
32 Critical
166 Important
0 Moderate
0 Low
Microsoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days.
Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.
This month’s update includes patches for:
.NET
Sans Isc
Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)
blogs_sans_isc·2026-06-09·CVSS 8.8
CVE-2026-49160 [HIGH] Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)
Microsoft June 2026 Patch Tuesday
Published: 2026-06-09. Last Updated: 2026-06-09 17:34:29 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and do not require any user action. In addition, Microsoft incorporated 360 different vulnerabilities affecting Chromium into its Edge browser.
This is certainly a busier-than-usual patch Tuesday. In particular, the large number of patched Chromium/Edge vulnerabilities underscores the impact of AI tools on vulnerability discovery.
Some noteworthy vulnerabilities:
CVE-2026-49160: This vulnerability was made public a week ago. As implem
Rapid7
Patch Tuesday - June 2026
blogs_rapid7·2026-06-09·CVSS 7.8
CVE-2026-33825 [HIGH] Patch Tuesday - June 2026
Microsoft is publishing 200 vulnerabilities on June 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild for any of these vulnerabilities, and is aware of public disclosure for three. This is similar to last month’s Patch Tuesday, however several of last month’s vulnerabilities ended up on CISA KEV in the days following their publication. So far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years. As usual, browser vulns are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update G
Bleepingcomputer
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
blogs_bleepingcomputer·2026-06-09·CVSS 7.8
CVE-2026-45586 [HIGH] Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
## Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
## Lawrence Abrams
65 Elevation of Privilege Vulnerabilities
19 Security Feature Bypass Vulnerabilities
55 Remote Code Execution Vulnerabilities
30 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
27 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.
Therefore, the number of flaws does not include flaws in Mariner, Azure HorizonDB, Microsoft Copilot, Copilot Chat, M365 Copilot, Microsoft Exchange Online, and Microsoft Graph that were fixed by Microsoft earlier this month.
There were also a massive 360 Microsoft Edge/Chromium flaws that were fixed by Google this month, which were excluded from this Patch
2026-06-09
Published