Impact
The flaw arises from an uninitialized resource in the Windows Remote Desktop Protocol client, allowing an unauthorized attacker to read sensitive data from the system over the network. This weakness, classified as CWE‑908, enables exposure of confidential information but does not provide privilege escalation or code execution. The consequence is a loss of confidentiality for data that may be transmitted or processed during an RDP session.
Affected Systems
Microsoft Windows 10 (Versions 1607, 1809, 21H2, 22H2) and Windows 11 (Versions 24H2, 25H2, 26H1) are affected, as well as all listed Windows Server editions from 2012 through 2025, including their Server Core installations. All these versions are susceptible according to the CNA data.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity. The EPSS score of <1% indicates a low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the Remote Desktop Protocol service over the network without authentication, triggering the flaw by exploiting uninitialized state handling. Because no special privileges or authentication are required, the attack can be performed from any networked host, but the low EPSS score suggests the overall risk remains moderate.
OpenCVE Enrichment