Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinternet-facing-service-vulnerabilitydetection-content-update

Microsoft Patches Critical Remote Desktop Client and HTTP.sys RCE Flaws

Updated 6d agoFirst seen Jun 9, 202620 sources

Microsoft’s June 2026 Patch Tuesday delivered a record-setting security release, with reports citing 206 to 208 CVEs addressed across Windows, Office, Azure, SQL Server, and other products, including 32 critical issues. Among the most urgent were multiple Remote Desktop Client remote code execution flaws—CVE-2026-42985, CVE-2026-47289, CVE-2026-44801, CVE-2026-44799, and CVE-2026-48563—that could let an attacker run code on a victim system if the user connected to a malicious Remote Desktop Server or accepted a specially crafted RDP certificate. Microsoft rated CVE-2026-42985 as more likely to be exploited, while the others were assessed as less likely at publication; several of the bugs were credited to Kyeongmin Kim of KAIST Hacking Lab.

Microsoft also disclosed CVE-2026-47291, a critical HTTP.sys remote code execution vulnerability with a CVSS 9.8 score that can be exploited remotely without authentication or user interaction by sending a specially crafted packet to a server using the Windows HTTP Protocol Stack. Microsoft said systems using the default MaxRequestBytes setting are not affected, but warned that servers with higher values may be vulnerable and advised administrators to set the registry value to a safe level and restart the HTTP service or host until patches are applied. Cisco Talos published Snort coverage for many of the newly disclosed flaws, while separate reporting also highlighted one actively exploited zero-day in Microsoft Defender and additional high-risk issues in Hyper-V, DHCP Client, Secure Boot, and UEFI components.

Share:
Microsoft Patches Critical Remote Desktop Client and HTTP.sys RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 13, 20266d ago

Microsoft publishes CVE-2026-11824 advisory

Microsoft's Security Response Center published an advisory page for CVE-2026-11824 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories
Jun 12, 20267d ago

Microsoft publishes CVE-2025-49697 advisory

Microsoft's Security Response Center published an advisory page for CVE-2025-49697 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories

Microsoft publishes CVE-2025-49673 advisory

Microsoft's Security Response Center published an advisory page for CVE-2025-49673 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories

Microsoft publishes CVE-2025-48824 advisory

Microsoft's Security Response Center published an advisory page for CVE-2025-48824 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories
Jun 9, 20269d ago

Cisco Talos releases Snort coverage for June Patch Tuesday flaws

Following Microsoft's June 2026 Patch Tuesday disclosures, Cisco Talos published Snort coverage for many of the newly disclosed vulnerabilities. Talos specifically highlighted CVE-2026-42985, CVE-2026-47291, CVE-2026-44803, and CVE-2026-44812 as prominent issues and advised users to update to the latest rulesets.

Microsoft Patch Tuesday for June 2026 - Snort rules and prominent vulnerabilities - Malware News - Malware Analysis, News and Indicators

Microsoft publishes CVE-2026-45607 for Windows Hyper-V

On 2026-06-09, Microsoft received and published CVE-2026-45607, an out-of-bounds read vulnerability in Windows Hyper-V that could allow local code execution. The entry referenced Microsoft's Security Response Center update guide and classified the issue as high severity.

CVE-2026-45607 - Windows Hyper-V Remote Code Execution Vulnerability

Microsoft discloses critical HTTP.sys RCE and mitigation guidance

On 2026-06-09, Microsoft disclosed CVE-2026-47291, a critical Windows HTTP.sys remote code execution vulnerability that is network-exploitable without authentication or user interaction. Microsoft said exploitation was more likely, released a fix, and advised administrators to set MaxRequestBytes to a safe value and restart the HTTP service or system as a mitigation before patching.

CVE-2026-47291 - Security Update Guide - Microsoft - HTTP.sys Remote Code Execution Vulnerability

Microsoft discloses multiple critical Remote Desktop Client RCE flaws

On 2026-06-09, Microsoft disclosed several critical Remote Desktop Client remote code execution vulnerabilities, including CVE-2026-42985, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, and CVE-2026-48563. Microsoft said fixes were available for these issues and stated they were not publicly disclosed or exploited at publication, while rating CVE-2026-42985 as more likely to be exploited.

CVE-2026-42985 - Security Update Guide - Microsoft - Remote Desktop Client Remote Code Execution Vulnerability

Microsoft issues June 2026 Patch Tuesday security updates

On 2026-06-09, Microsoft released its June 2026 Patch Tuesday updates, addressing a record-breaking set of vulnerabilities across its product portfolio. Sources describe the release as fixing 206 Microsoft vulnerabilities, while another report counts 208 Microsoft CVEs and 571 total when Chromium and bundled third-party components are included.

Microsoft Patch Tuesday for June 2026 - Snort rules and prominent vulnerabilities - Malware News - Malware Analysis, News and Indicators
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

80 LINKEDOpen in app
Vulnerabilities
50 linked
HTTP.sys Remote Code Execution VulnerabilityGreenPlasma / Windows Collaborative Translation Framework (CTFMON) Elevation of PrivilegeWindows Kernel TCP/IP Use-After-Free Remote Code ExecutionWindows BitLocker Security Feature Bypass (Bitskrieg/YellowKey-related)Windows DHCP Client Service Remote Code Execution VulnerabilityHTTP.sys HTTP/2 Bomb Denial of ServiceYellowKeyRedSun - Microsoft Defender Elevation of PrivilegeRemote Code Execution in Microsoft Remote Desktop ClientRemote Code Execution in Windows Remote Desktop ClientWindows Hyper-V Out-of-Bounds Read Remote Code Execution VulnerabilityRemote Code Execution in Microsoft Remote Desktop ClientRemote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution in Microsoft Remote Desktop ClientAzure HorizonDB Authentication Bypass by Spoofing Elevation of Privilege VulnerabilityInformation Disclosure in Microsoft GraphImproper Authorization Information Disclosure in Microsoft Exchange OnlineSearchLeak information disclosure in Microsoft 365 Copilot EnterpriseInformation Disclosure in Copilot Chat (Microsoft Edge)Remote Code Execution in Microsoft M365 CopilotWindows NT OS Kernel Integer Underflow Elevation of PrivilegeRemote Desktop Client Heap-Based Buffer Overflow RCEWindows Graphics Component RCE in Win32K-GRFXWindows BitLocker Device Encryption Security Feature BypassMicrosoft Office Out-of-Bounds Read Information Disclosure VulnerabilityMicrosoft SharePoint Server Cross-Site Scripting Spoofing VulnerabilityMicrosoft Outlook and Word Remote Code Execution VulnerabilityMicrosoft Graphics Component Use-After-Free Elevation of PrivilegeElevation of Privilege in Windows Device Health Attestation via Trust Boundary ViolationMicrosoft Office Preview Pane Use-After-Free Local Code ExecutionRemote Code Execution in Microsoft Outlook Classic and Word via Type ConfusionContainer Escape RCE in Microsoft Azure Kubernetes ServiceRemote Code Execution in Nuance PowerScribeRCE in Windows Hyper-V via Out-of-Bounds ReadMicrosoft Office Local Code Execution via Heap-Based Buffer OverflowRemote Code Execution in Windows Active Directory Domain ServicesWindows Graphics Component RCE in Win32K GRFXRCE in Windows Kerberos Key Distribution Center (KDC)Elevation of Privilege in Linux MANA Driver for Microsoft Azure Network AdapterWinlogon Elevation of Privilege VulnerabilityMicrosoft SharePoint Server XSS Spoofing VulnerabilityWindows DWM Core Library Elevation of Privilege VulnerabilityMicrosoft Office Use-After-Free Remote Code Execution VulnerabilityRemote Code Execution in Microsoft Outlook and Word via Preview PaneRemote Code Execution in Microsoft Remote Desktop ClientMicrosoft Office Use-After-Free Remote Code Execution VulnerabilityRemote Code Execution in Windows Deployment ServicesImproper Authentication Elevation of Privilege in Windows Cryptographic ServicesWindows Hyper-V Guest-to-Host RCE via Out-of-Bounds ReadRCE in Windows Media
Malware
1 linked
Affected products
23 linked
Microsoft OfficeChromiumMicrosoft DefenderRemote Desktop ClientAzure Kubernetes ServiceSharepoint ServerExchange OnlinePowershellBitlockerWindows KernelWindows Hyper-VWindows MediaWindows Deployment ServicesWindows Http.SysMicrosoft 365 CopilotMicrosoft Graphics ComponentActive Directory Domain ServicesHyper-VWindows Cryptographic ServicesCopilot ChatMicrosoft-GraphAzure HorizondbPowerscribe
Organizations
6 linked
Microsoft CorporationTrend MicroSecurity AffairsKorea Advanced Institute of Science and TechnologyCisco SystemsKorea Advanced Institute of Science and Technology Hacking Lab
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.