Executive brief
A security vulnerability exists in the Windows Remote Desktop Protocol (RDP), a feature used to remotely access and control computers over a network. An attacker could exploit this flaw to gain access to sensitive information that should otherwise be protected. While the attack can be launched over the network, it requires a user to take a specific action, such as clicking a link or opening a malicious file, before the attacker can view the data.
Technical details
This vulnerability is classified as a 'Use of Uninitialized Resource' (CWE-908) within the Windows Remote Desktop Protocol (RDP) implementation. An unauthenticated attacker can exploit this over the network to disclose sensitive information from the memory of the affected system. The attack requires user interaction, meaning a target user must be induced to perform an action (such as connecting to a malicious RDP server or clicking a crafted link) to trigger the leak. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions including Server Core
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft