Junglewise Threat Intelligence

CVE-2026-55003: Microsoft Windows RDP information disclosure via uninitialized resource

CVE-2026-55003 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2012, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Remote Desktop Protocol (RDP) could allow an unauthorized attacker to access sensitive information over a network. RDP is a common tool used for remote administration and telework. If exploited, this could lead to the exposure of system memory or other confidential data, potentially aiding further attacks against the organization.

Technical details

A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists in the Windows Remote Desktop Protocol (RDP) implementation. An unauthenticated attacker can exploit this over the network by enticing a user to interact with a malicious RDP session or resource. Successful exploitation allows the attacker to disclose sensitive information from the system's memory. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012, and has been addressed in Microsoft's July 2026 security updates.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: patched: Security updates released by Microsoft.

References

Related threats