Executive brief
A security vulnerability in Microsoft's Remote Desktop Web Client and Windows Admin Center could allow an unauthorized person to access private personal information over the network. This tool is commonly used by IT staff to manage servers and by employees to access office computers remotely. An exploit could lead to the exposure of sensitive user data, potentially compromising privacy and providing attackers with information useful for further attacks.
Technical details
This vulnerability is classified as an exposure of private personal information (CWE-359) within the Microsoft Remote Desktop Web Client and Windows Admin Center. The flaw allows an unauthenticated attacker to disclose sensitive information over the network, though it requires some level of user interaction (UI:R). The root cause involves improper handling of data within the RDP web interface components. Affected versions include Remote Desktop Web Client versions prior to 2.1.65.2 and Windows Admin Center versions prior to 2.7.4. Microsoft has released updates to address this information disclosure risk.
Affected products
- Microsoft Remote Desktop Web Client 2.0.0.0 to 2.1.65.2
- Microsoft Windows Admin Center 1809.0 to 2.7.4
Timeline
- 2026-07-17: advisory: Initial disclosure by Microsoft and NVD publication.