PT-2026-40213 · Microsoft · Windows Remote Desktop+1

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-40398

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Remote Desktop (affected versions not specified)
Description A heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. This issue occurs at the Remote Desktop Services (RDS) trust boundary.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-06636
CVE-2026-40398

Affected Products

Windows
Windows Remote Desktop