CVE-2026-61363

microsoft windows_10_1607: Heap-basierter Pufferueberlauf

Affected

  • microsoft/windows_10_1607 lt *..10.0.14393.9418
  • microsoft/windows_10_1607 lt *..10.0.14393.9418
  • microsoft/windows_10_1809 lt *..10.0.17763.9115
  • microsoft/windows_10_1809 lt *..10.0.17763.9115
  • microsoft/windows_10_21h2 lt *..10.0.19044.7663
  • microsoft/windows_10_21h2 lt *..10.0.19044.7663
  • microsoft/windows_10_21h2 lt *..10.0.19044.7663
  • microsoft/windows_10_22h2 lt *..10.0.19045.7663
  • microsoft/windows_10_22h2 lt *..10.0.19045.7663
  • microsoft/windows_10_22h2 lt *..10.0.19045.7663
  • microsoft/windows_11_23h2 lt *..10.0.22631.7517
  • microsoft/windows_11_23h2 lt *..10.0.22631.7517
  • microsoft/windows_11_24h2 lt *..10.0.26100.9106
  • microsoft/windows_11_24h2 lt *..10.0.26100.9106
  • microsoft/windows_11_25h2 lt *..10.0.26200.9106
  • microsoft/windows_11_25h2 lt *..10.0.26200.9106
  • microsoft/windows_11_26h1 lt *..10.0.28000.2704
  • microsoft/windows_11_26h1 lt *..10.0.28000.2704
  • microsoft/windows_server_2016 lt *..10.0.14393.9418
  • microsoft/windows_server_2019 lt *..10.0.17763.9115
  • microsoft/windows_server_2022 lt *..10.0.20348.5440
  • microsoft/windows_server_2025 lt *..10.0.26100.33222

Description

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Affected operating systems

  • windows

    microsoft / windows_10_1607

  • windows

    microsoft / windows_10_1809

  • windows

    microsoft / windows_10_21h2

  • windows

    microsoft / windows_10_22h2

  • windows

    microsoft / windows_11_23h2

  • windows

    microsoft / windows_11_24h2

  • windows

    microsoft / windows_11_25h2

  • windows

    microsoft / windows_11_26h1

  • windows

    microsoft / windows_server_2012r2

  • windows

    microsoft / windows_server_2012

  • windows

    microsoft / windows_server_2016

  • windows

    microsoft / windows_server_2019

  • windows

    microsoft / windows_server_2022

  • windows

    microsoft / windows_server_2025

Metrics

8.1
Source: nvd-v3
51.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-11 17:05 UTC
CWE-122, CWE-20

Weakness classes (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →
  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-16 19:16 UTC· secure@microsoft.com
    • Affected: Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17) → Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17)
  2. CVE Modified2026-08-11 22:17 UTC· secure@microsoft.com
    • Affected: Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17) → Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17)
  3. New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
    • Affected: Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17)
    • Description: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
    • CWE: CWE-20

Linked advisories