Executive brief
A critical vulnerability exists in the Windows Remote Desktop Protocol (RDP), which is used to remotely access and manage computers. An unauthorized attacker can exploit this flaw over a network to take full control of a vulnerable system without any user interaction. This could lead to complete data theft, system outages, or the deployment of ransomware across the corporate network.
Technical details
A remote code execution vulnerability exists in the Microsoft Windows Remote Desktop Protocol (RDP) due to the use of an uninitialized resource (CWE-908). The flaw allows an unauthenticated, remote attacker to send specially crafted requests to a target system's RDP service. Successful exploitation enables the attacker to execute arbitrary code with high privileges on the host system. The vulnerability is network-exploitable with low complexity and requires no user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
- 2026-07-14: advisory: MSRC advisory released.