CVE-2026-32157Disclosure(microsoft / remote_desktop_client)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft remote_desktop_client systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • remote_desktop_client
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
remote_desktop_clientwindows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-15: 2Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-17: 104-1404-1504-17
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure1Patch1
2026-04-152
General2
2026-04-171
Disclosure1
Full discourse5 posts
  • Autumn Good@autumn_good_35
    General

    今月気になるのはワーム化の可能性があるWindows TCP/IPのRCE(CVE-2026-33827)やWindows IKE拡張機能のRCE(CVE-2026-33824)、APT29が悪用しそうなRDPクライアントのRCE(CVE-2026-32157)ですね。 Zero Day Initiative — The April 2026 Security Update Review https://www.zerodayinitiative.com/blog/2026/4/14/the-april-2026-security-update-review

    Post summary

    The post lists three Windows RCE CVEs with some technical context, noting possible worm usage and APT29 relevance, but provides no PoC, exploit code, or patch information.

    330541.9K
    6.9K followersView on X
  • Patel Mahendra@Mahendrak29
    General

    https://whatsapp.com/channel/0029VbAre6eKQuJNLsryuQ0u/112 🔴 Zero-Day CVE-2026-32201 – SharePoint Spoofing CVE-2026-33825 – Publicly Disclosed 🔴 Critical: CVE-2026-33827 – Windows RCE CVE-2026-33826 – Active Directory RCE CVE-2026-32157 – RDP Client RCE CVE-2026-32190 – Microsoft Office RCE #cyber

    Post summary

    The post lists several 2026 CVEs with brief classifications (e.g., RCE, spoofing) but provides no proof‑of‑concept, exploit code, patch details, or evidence of active exploitation.

    00010239
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32157 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-32157

    Post summary

    The text announces CVE-2026-32157, a use‑after‑free vulnerability in Remote Desktop Client that allows remote code execution by unauthorized attackers.

    00000106
    57.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Windows (CVE-2026-32157) https://vuldb.com/vuln/357488

    Post summary

    The message announces that CVE-2026-32157, a severe vulnerability against Microsoft Windows, has been disclosed, but provides no further technical or remediation details.

    0000074
    2.1K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-32157 | Microsoft Remote Desktop client for Windows Desktop | Remote Code Execution Description A use-after-free vulnerability in Microsoft Remote Desktop client for Windows Desktop enables unauth attackers to achieve RCE over a network by triggering memory corruption during client processing. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Microsoft Remote Desktop client for Windows Desktop Affected Version: >= 1.2.0.0 and < 2.0.1070.0 Sources Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32157

    Post summary

    CVE-2026-32157 is a high‑severity RCE vulnerability in Microsoft Remote Desktop client with an available patch, but no public PoC or known active exploitation.

    0000045
    8 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftremote_desktop_client-windows-
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more