Executive brief
A security vulnerability has been identified in the Windows Remote Desktop Protocol (RDP), a feature used to remotely access and manage computers. An attacker could exploit this flaw to view sensitive information stored in the computer's memory that they should not have access to. While the attack can be carried out over a network, it requires a user to perform a specific action, such as clicking a link or opening a malicious file, to be successful.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. The flaw allows an unauthenticated remote attacker to disclose sensitive information by inducing a user to interact with a malicious resource. The vulnerability stems from improper bounds checking when RDP processes specific data packets, potentially allowing memory contents to be leaked across the network. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions including Server Core
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed