Executive brief
A vulnerability in the Windows Remote Desktop Protocol (RDP) could allow an authorized user to access information they are not supposed to see. RDP is a common tool used for remote administration and telework. While an attacker must already have login credentials to exploit this, it could lead to the exposure of sensitive system data or memory contents.
Technical details
This vulnerability (CWE-908) exists in the Windows Remote Desktop Protocol (RDP) due to the use of an uninitialized resource. An attacker with low-privileged credentials can exploit this over the network without user interaction to disclose sensitive information from the system's memory. The flaw is categorized as an information disclosure vulnerability with high confidentiality impact but no impact on integrity or availability. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory