WSL bundles msrdc.exe and the NuGet package Microsoft.RemoteDesktop.Client.MSRDC.SessionHost, currently pinned to 1.2.6353 in packages.config. This version is flagged by vulnerability scanners (e.g. Qualys QID 92381) for CVE-2026-32157, a use-after-free RCE in the Remote Desktop client. The standalone Remote Desktop client was patched in 1.2.7099.0, but the WSL-bundled SessionHost package still ships the older build.
WSL bundles msrdc.exe and the NuGet package Microsoft.RemoteDesktop.Client.MSRDC.SessionHost, currently pinned to 1.2.6353 in packages.config. This version is flagged by vulnerability scanners (e.g. Qualys QID 92381) for CVE-2026-32157, a use-after-free RCE in the Remote Desktop client. The standalone Remote Desktop client was patched in 1.2.7099.0, but the WSL-bundled SessionHost package still ships the older build.