Executive brief
Windows Remote Desktop Services (RDS) is Microsoft's technology that allows users to access Windows desktops and applications from remote locations. An authorized attacker can exploit an out-of-bounds read vulnerability to access sensitive information on a system, potentially revealing credentials, encryption keys, or other confidential data that could be used in further attacks.
Technical details
The vulnerability is an out-of-bounds read in Windows Remote Desktop Services that allows disclosure of information. The attack requires the attacker to be authenticated or have local access to the affected system. By reading memory beyond allocated buffer boundaries, an attacker can extract sensitive data from the RDS process. No code execution capability is implied; the threat is limited to information disclosure. A patch from Microsoft is expected or may already be available through Windows Update.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed