CVE-2026-61363
microsoft windows_10_1607: Heap-basierter Pufferueberlauf
Affected
- microsoft/windows_10_1607
lt *..10.0.14393.9418 - microsoft/windows_10_1607
lt *..10.0.14393.9418 - microsoft/windows_10_1809
lt *..10.0.17763.9115 - microsoft/windows_10_1809
lt *..10.0.17763.9115 - microsoft/windows_10_21h2
lt *..10.0.19044.7663 - microsoft/windows_10_21h2
lt *..10.0.19044.7663 - microsoft/windows_10_21h2
lt *..10.0.19044.7663 - microsoft/windows_10_22h2
lt *..10.0.19045.7663 - microsoft/windows_10_22h2
lt *..10.0.19045.7663 - microsoft/windows_10_22h2
lt *..10.0.19045.7663 - microsoft/windows_11_23h2
lt *..10.0.22631.7517 - microsoft/windows_11_23h2
lt *..10.0.22631.7517 - microsoft/windows_11_24h2
lt *..10.0.26100.9106 - microsoft/windows_11_24h2
lt *..10.0.26100.9106 - microsoft/windows_11_25h2
lt *..10.0.26200.9106 - microsoft/windows_11_25h2
lt *..10.0.26200.9106 - microsoft/windows_11_26h1
lt *..10.0.28000.2704 - microsoft/windows_11_26h1
lt *..10.0.28000.2704 - microsoft/windows_server_2016
lt *..10.0.14393.9418 - microsoft/windows_server_2019
lt *..10.0.17763.9115 - microsoft/windows_server_2022
lt *..10.0.20348.5440 - microsoft/windows_server_2025
lt *..10.0.26100.33222
Description
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Affected operating systems
windows
microsoft / windows_10_1607
windows
microsoft / windows_10_1809
windows
microsoft / windows_10_21h2
windows
microsoft / windows_10_22h2
windows
microsoft / windows_11_23h2
windows
microsoft / windows_11_24h2
windows
microsoft / windows_11_25h2
windows
microsoft / windows_11_26h1
windows
microsoft / windows_server_2012r2
windows
microsoft / windows_server_2012
windows
microsoft / windows_server_2016
windows
microsoft / windows_server_2019
windows
microsoft / windows_server_2022
windows
microsoft / windows_server_2025
Metrics
Show all metrics
Weakness classes (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-16 19:16 UTC· secure@microsoft.com
- Affected: Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17) → Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17)
- CVE Modified2026-08-11 22:17 UTC· secure@microsoft.com
- Affected: Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17) → Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17)
- New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
- Affected: Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2 (+17)
- Description: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVSS V3.1: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE: CWE-20