Description
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises from an uninitialized resource in the Windows Remote Desktop Protocol client, allowing an unauthorized attacker to read sensitive data from the system over the network. This weakness, classified as CWE‑908, enables exposure of confidential information but does not provide privilege escalation or code execution. The consequence is a loss of confidentiality for data that may be transmitted or processed during an RDP session.

Affected Systems

Microsoft Windows 10 (Versions 1607, 1809, 21H2, 22H2) and Windows 11 (Versions 24H2, 25H2, 26H1) are affected, as well as all listed Windows Server editions from 2012 through 2025, including their Server Core installations. All these versions are susceptible according to the CNA data.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as medium severity. The EPSS score of <1% indicates a low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the Remote Desktop Protocol service over the network without authentication, triggering the flaw by exploiting uninitialized state handling. Because no special privileges or authentication are required, the attack can be performed from any networked host, but the low EPSS score suggests the overall risk remains moderate.

Generated by OpenCVE AI on July 31, 2026 at 08:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the official Microsoft update that addresses CVE‑2026‑50376 from the Microsoft Security Response Center.
  • Where immediate update application is not possible, limit RDP exposure by configuring the firewall to allow connections only from trusted IP ranges or by disabling the Remote Desktop port entirely.
  • After applying the fix or applying a network restriction, regularly review Windows Event Log entries for RDP authentication attempts and investigate any anomalies.

Generated by OpenCVE AI on July 31, 2026 at 08:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Title Windows Remote Desktop Client Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-908
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:24.138Z

Reserved: 2026-06-04T18:55:14.744Z

Link: CVE-2026-50376

cve-icon Vulnrichment

Updated: 2026-07-15T14:16:17.236Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:15:04Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource