Executive brief
A security vulnerability exists in the Windows Remote Desktop Protocol (RDP), which is commonly used for remote access to computers and servers. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored in the system's memory. While the attack can be performed over a network, it requires some level of user interaction to be successful.
Technical details
An information disclosure vulnerability exists in the Microsoft Remote Desktop Protocol (RDP) due to an off-by-one error (CWE-193) and the use of uninitialized resources (CWE-908). An unauthenticated attacker can exploit this over the network by inducing a user to interact with a malicious RDP session or server. Successful exploitation allows the attacker to read sensitive data from the memory of the affected system. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2012 to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard and Server Core
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: advisory: Microsoft Security Response Center advisory published