Executive brief
A security vulnerability has been identified in the Windows Remote Desktop Protocol (RDP), which is commonly used for remote access to computers and servers. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored in the system's memory. While the attack can be carried out over a network, it requires a user to perform a specific action, such as clicking a malicious link or connecting to a rogue server, before the data can be stolen.
Technical details
A buffer over-read vulnerability (CWE-126) exists in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. The flaw allows an unauthenticated, remote attacker to read data from the memory of an affected system. Exploitation requires user interaction, typically involving a user connecting to a malicious RDP server or clicking a crafted link. Successful exploitation results in high confidentiality impact as the attacker can disclose information that should be protected by memory boundaries. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard and Server Core
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft