Junglewise Threat Intelligence

CVE-2026-50497: Microsoft Windows Remote Desktop Protocol information disclosure

CVE-2026-50497 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Remote Desktop Protocol (RDP), which is commonly used for remote access to computers and servers. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored in the system's memory. While the attack can be performed over a network, it requires some level of user interaction to be successful.

Technical details

An information disclosure vulnerability exists in the Microsoft Remote Desktop Protocol (RDP) due to an off-by-one error (CWE-193) and the use of uninitialized resources (CWE-908). An unauthenticated attacker can exploit this over the network by inducing a user to interact with a malicious RDP session or server. Successful exploitation allows the attacker to read sensitive data from the memory of the affected system. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2012 to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD
  • 2026-07-14: advisory: Microsoft Security Response Center advisory published

References

Related threats