Junglewise Threat Intelligence

CVE-2026-50376: Microsoft Windows RDP information disclosure via uninitialized resource

CVE-2026-50376 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Remote Desktop Protocol (RDP), which is used to remotely access and manage computers. An attacker could exploit this flaw to view sensitive information that they should not have access to. While the attack can be carried out over a network, it requires a user to perform a specific action, such as clicking a link or opening a malicious file, before the attacker can capture data.

Technical details

This vulnerability is classified as a 'Use of Uninitialized Resource' (CWE-908) within the Windows Remote Desktop Protocol (RDP) implementation. An unauthenticated attacker can exploit this over the network to disclose sensitive information from the target system's memory. Although the attack vector is network-based, the CVSS vector indicates that user interaction is required (UI:R) to trigger the exploit. The flaw stems from the system failing to properly initialize a resource before it is used or transmitted, potentially leaking data to an unauthorized party. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core installations

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-07-14: advisory: NVD record published

References

Related threats