Junglewise Threat Intelligence

CVE-2026-42908: Microsoft Windows RDP out-of-bounds read

CVE-2026-42908 · Severity: high · CVSS 7.5 · Published 2026-06-09

Executive brief

A security vulnerability has been identified in the Windows Remote Desktop Protocol (RDP), which is used to remotely access and manage computers. An unauthorized attacker could exploit this flaw over a network to access sensitive information that should otherwise be protected. This could lead to the exposure of system memory or configuration details, potentially aiding further attacks against the organization.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. The flaw is triggered when the RDP service improperly handles specially crafted network packets, allowing an attacker to read data beyond the intended buffer. This is a network-based attack that requires no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation results in the unauthorized disclosure of information from the memory space of the RDP service. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows Remote Desktop Protocol (RDP)

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Published by Microsoft and NVD

References

Related threats