Executive brief
Windows Remote Desktop Licensing Service contains an out-of-bounds read vulnerability that allows an authorized local attacker to disclose sensitive information. This affects systems where Remote Desktop services are enabled and could lead to exposure of security-sensitive data stored in system memory.
Technical details
An out-of-bounds read vulnerability exists in the Windows Remote Desktop Licensing Service, allowing an authorized local attacker to read memory beyond the bounds of allocated buffers. The vulnerability requires authentication and local access to the affected system. Successful exploitation permits disclosure of sensitive information from kernel or service memory. This is a non-arbitrary read limited to adjacent memory regions, making it useful for information disclosure rather than code execution. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed