Executive brief
A security vulnerability exists in the Windows Remote Desktop Protocol (RDP), which is commonly used for remote access to computers and servers. An attacker could exploit this flaw to gain access to sensitive information stored in the system's memory. While the attack can be initiated over a network, it requires a user to perform a specific action, such as clicking a link or opening a malicious file, to be successful.
Technical details
A vulnerability classified as 'Use of Uninitialized Resource' (CWE-908) exists in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. The flaw allows an unauthenticated, remote attacker to disclose sensitive information from the memory of an affected system. Exploitation requires user interaction, typically involving a victim connecting to a malicious RDP server or interacting with a malicious link. The vulnerability stems from the system failing to properly initialize a resource before it is accessed or transmitted over the network. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All installations
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication