Heap-based buffer overflow in Microsoft Windows and Windows Server - CVE-2026-69518

 

Heap-based buffer overflow in Microsoft Windows and Windows Server - CVE-2026-69518

Published: September 8, 2026


Vulnerability identifier: #VU147765
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69518
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in Windows Remote Desktop when processing specially crafted clipboard data in a Remote Desktop sharing session. A remote attacker can join a Remote Desktop sharing session and send specially crafted clipboard data to execute arbitrary code.

User interaction is required to initiate or participate in the sharing session.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2026-69518

Install security update from vendor's website.

Microsoft Windows - addressed in versions 10 21H2 10.0.19044.7725, 10 22H2 10.0.19045.7725, 10 1607 10.0.14393.9512, 10 1809 10.0.17763.9245, 11 23H2 10.0.22631.7582, 11 24H2 10.0.26100.9445, 11 25H2 10.0.26200.9445, 11 26H1 10.0.28000.2954
Windows Server - addressed in versions 2012 R2 6.3.9600.23397, 2012 6.2.9200.26349, 2016 10.0.14393.9512, 2019 10.0.17763.9245, 2022 10.0.20348.5622, 2025 10.0.26100.33438

External References

Related Security Bulletins