Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinternet-facing-service-vulnerabilitydetection-content-update

Microsoft Patches Critical Remote Desktop Client and HTTP.sys RCE Flaws

Updated 17h agoFirst seen Jun 9, 202620 sources

Microsoft’s June 2026 Patch Tuesday delivered a record-setting security release, with reports citing 206 to 208 CVEs addressed across Windows, Office, Azure, SQL Server, and other products, including 32 critical issues. Among the most urgent were multiple Remote Desktop Client remote code execution flaws—CVE-2026-42985, CVE-2026-47289, CVE-2026-44801, CVE-2026-44799, and CVE-2026-48563—that could let an attacker run code on a victim system if the user connected to a malicious Remote Desktop Server or accepted a specially crafted RDP certificate. Microsoft rated CVE-2026-42985 as more likely to be exploited, while the others were assessed as less likely at publication; several of the bugs were credited to Kyeongmin Kim of KAIST Hacking Lab.

Microsoft also disclosed CVE-2026-47291, a critical HTTP.sys remote code execution vulnerability with a CVSS 9.8 score that can be exploited remotely without authentication or user interaction by sending a specially crafted packet to a server using the Windows HTTP Protocol Stack. Microsoft said systems using the default MaxRequestBytes setting are not affected, but warned that servers with higher values may be vulnerable and advised administrators to set the registry value to a safe level and restart the HTTP service or host until patches are applied. Cisco Talos published Snort coverage for many of the newly disclosed flaws, while separate reporting also highlighted one actively exploited zero-day in Microsoft Defender and additional high-risk issues in Hyper-V, DHCP Client, Secure Boot, and UEFI components.

Share:
Microsoft Patches Critical Remote Desktop Client and HTTP.sys RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 13, 202617h ago

Microsoft publishes CVE-2026-11824 advisory

Microsoft's Security Response Center published an advisory page for CVE-2026-11824 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories
Jun 12, 20262d ago

Microsoft publishes CVE-2025-49697 advisory

Microsoft's Security Response Center published an advisory page for CVE-2025-49697 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories

Microsoft publishes CVE-2025-49673 advisory

Microsoft's Security Response Center published an advisory page for CVE-2025-49673 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories

Microsoft publishes CVE-2025-48824 advisory

Microsoft's Security Response Center published an advisory page for CVE-2025-48824 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.

Msrc Product Advisories
Jun 9, 20264d ago

Cisco Talos releases Snort coverage for June Patch Tuesday flaws

Following Microsoft's June 2026 Patch Tuesday disclosures, Cisco Talos published Snort coverage for many of the newly disclosed vulnerabilities. Talos specifically highlighted CVE-2026-42985, CVE-2026-47291, CVE-2026-44803, and CVE-2026-44812 as prominent issues and advised users to update to the latest rulesets.

Microsoft Patch Tuesday for June 2026 - Snort rules and prominent vulnerabilities - Malware News - Malware Analysis, News and Indicators

Microsoft publishes CVE-2026-45607 for Windows Hyper-V

On 2026-06-09, Microsoft received and published CVE-2026-45607, an out-of-bounds read vulnerability in Windows Hyper-V that could allow local code execution. The entry referenced Microsoft's Security Response Center update guide and classified the issue as high severity.

CVE-2026-45607 - Windows Hyper-V Remote Code Execution Vulnerability

Microsoft discloses critical HTTP.sys RCE and mitigation guidance

On 2026-06-09, Microsoft disclosed CVE-2026-47291, a critical Windows HTTP.sys remote code execution vulnerability that is network-exploitable without authentication or user interaction. Microsoft said exploitation was more likely, released a fix, and advised administrators to set MaxRequestBytes to a safe value and restart the HTTP service or system as a mitigation before patching.

CVE-2026-47291 - Security Update Guide - Microsoft - HTTP.sys Remote Code Execution Vulnerability

Microsoft discloses multiple critical Remote Desktop Client RCE flaws

On 2026-06-09, Microsoft disclosed several critical Remote Desktop Client remote code execution vulnerabilities, including CVE-2026-42985, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, and CVE-2026-48563. Microsoft said fixes were available for these issues and stated they were not publicly disclosed or exploited at publication, while rating CVE-2026-42985 as more likely to be exploited.

CVE-2026-42985 - Security Update Guide - Microsoft - Remote Desktop Client Remote Code Execution Vulnerability

Microsoft issues June 2026 Patch Tuesday security updates

On 2026-06-09, Microsoft released its June 2026 Patch Tuesday updates, addressing a record-breaking set of vulnerabilities across its product portfolio. Sources describe the release as fixing 206 Microsoft vulnerabilities, while another report counts 208 Microsoft CVEs and 571 total when Chromium and bundled third-party components are included.

Microsoft Patch Tuesday for June 2026 - Snort rules and prominent vulnerabilities - Malware News - Malware Analysis, News and Indicators
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

80 LINKEDOpen in app
Vulnerabilities
50 linked
Remote Code Execution in Windows HTTP.sysGreenPlasma / Windows Collaborative Translation Framework (CTFMON) Elevation of PrivilegeWindows Kernel TCP/IP Use-After-Free Remote Code ExecutionWindows BitLocker Security Feature Bypass (YellowKey/Bitskrieg)Windows DHCP Client Service Remote Code Execution VulnerabilityHTTP.sys HTTP/2 Bomb Denial of ServiceYellowKey BitLocker security feature bypass in WindowsRedSun: Microsoft Defender Link-Following Privilege EscalationRemote Code Execution in Microsoft Remote Desktop ClientRemote Code Execution in Windows Remote Desktop ClientWindows Hyper-V Out-of-Bounds Read Remote Code Execution VulnerabilityRemote Code Execution in Microsoft Remote Desktop ClientRemote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution in Windows Remote Desktop ClientAuthentication Bypass by Spoofing in Azure HorizonDBInformation Disclosure in Microsoft GraphImproper Authorization Information Disclosure in Microsoft Exchange OnlineCommand Injection in Microsoft M365 CopilotInformation Disclosure in Copilot Chat (Microsoft Edge)Remote Code Execution in Microsoft M365 CopilotWindows NT OS Kernel Elevation of Privilege VulnerabilityRemote Desktop Client Heap-Based Buffer Overflow RCERCE in Windows Win32K-GRFX via Integer Overflow or WraparoundWindows BitLocker Security Feature BypassInformation Disclosure in Microsoft Office via Out-of-Bounds ReadMicrosoft SharePoint Server Spoofing VulnerabilityType Confusion RCE in Microsoft Office Outlook/Word Preview RenderingMicrosoft Graphics Component Elevation of Privilege VulnerabilityElevation of Privilege in Windows Device Health Attestation via Trust Boundary ViolationUse-after-free in Microsoft OfficeRemote Code Execution Type Confusion in Microsoft Office via Outlook Classic/Word RenderingContainer Escape RCE in Microsoft Azure Kubernetes ServiceRemote Code Execution in Nuance PowerScribe via Deserialization of Untrusted DataRCE in Windows Hyper-V via Out-of-Bounds ReadLocal Code Execution in Microsoft Office via Heap-Based Buffer OverflowRemote Code Execution in Windows Active Directory Domain ServicesWindows Graphics Component RCE in Win32K GRFXRCE in Windows Kerberos Key Distribution Center (KDC)Elevation of Privilege in Linux MANA Driver for Microsoft Azure Network AdapterWinlogon Elevation of Privilege VulnerabilityMicrosoft SharePoint Server Cross-Site Scripting Spoofing VulnerabilityWindows DWM Core Library Elevation of Privilege VulnerabilityUse-after-free in Microsoft OfficeRCE in Microsoft Outlook and Word via Word rendering engineRemote Code Execution in Microsoft Remote Desktop ClientUse-after-free in Microsoft OfficeRemote Code Execution in Windows Deployment ServicesImproper Authentication Elevation of Privilege in Windows Cryptographic ServicesWindows Hyper-V Guest-to-Host RCE via Out-of-Bounds ReadRCE in Windows Media
Malware
1 linked
Affected products
23 linked
Microsoft OfficeChromiumMicrosoft DefenderRemote Desktop ClientAzure Kubernetes ServiceSharepoint ServerExchange OnlinePowershellBitlockerWindows KernelWindows Hyper-VWindows MediaWindows Deployment ServicesWindows Http.SysMicrosoft 365 CopilotMicrosoft Graphics ComponentActive Directory Domain ServicesHyper-VWindows Cryptographic ServicesCopilot ChatMicrosoft-GraphAzure HorizondbPowerscribe
Organizations
6 linked
Microsoft CorporationTrend MicroSecurity AffairsKorea Advanced Institute of Science and TechnologyCisco SystemsKorea Advanced Institute of Science and Technology Hacking Lab
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.