Executive brief
Microsoft Remote Desktop Client is a tool that allows users to connect to and control remote computers over a network. An authorized attacker could exploit an out-of-bounds read vulnerability to access sensitive information from the affected system's memory, potentially exposing credentials, encryption keys, or other confidential data.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Remote Desktop Client that allows an authorized attacker to disclose information over the network. The attack requires authentication (as indicated by "authorized attacker") and network connectivity to an affected system running the vulnerable client. Exploitation could enable memory disclosure attacks to extract sensitive data. Microsoft has addressed this vulnerability; patches are available via the Security Update Guide.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-09-08: disclosed