Skip to content

Update MSRDC.exe package to fix CVE-2026-32157 #40868

Description

@jbdeltra

WSL bundles msrdc.exe and the NuGet package Microsoft.RemoteDesktop.Client.MSRDC.SessionHost, currently pinned to 1.2.6353 in packages.config. This version is flagged by vulnerability scanners (e.g. Qualys QID 92381) for CVE-2026-32157, a use-after-free RCE in the Remote Desktop client. The standalone Remote Desktop client was patched in 1.2.7099.0, but the WSL-bundled SessionHost package still ships the older build.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions