Description
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer over-read in the Windows Remote Desktop Protocol (RDP) allows an unauthorized actor to read portions of memory that the RDP service should not expose, potentially revealing sensitive system or user data. This flaw is a classic example of CWE‑126, where improper bounds checking exposes confidential information. The resulting impact is a loss of confidentiality and the risk that critical data could be accessed by an attacker with no legitimate rights.

Affected Systems

Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including core installations. The vulnerability affects both x86 and x64 architectures, as well as ARM‑based builds for the listed Windows 11 releases.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity classification. With an EPSS score of less than 1%, the likelihood of exploitation at this time is low, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation occurs over the RDP service, requiring an attacker to reach the RDP port on the target machine; authentication is not indicated in the description, implying that the attack may be performed without user credentials. The likely attack vector is therefore remote network access to port 3389. The threat is chiefly a data‑disclosure risk rather than a privilege‑escalation or denial‑of‑service attack.

Generated by OpenCVE AI on July 31, 2026 at 08:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE‑2026‑50445 via the update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50445
  • Block or restrict access to the Remote Desktop Services port (TCP 3389) through the Windows firewall or network ACLs so only trusted networks can reach it
  • Monitor RDP logs for anomalous activity and ensure that the RDP service is not exposed to the public internet

Generated by OpenCVE AI on July 31, 2026 at 08:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Title Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-126
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:42.034Z

Reserved: 2026-06-04T18:57:47.376Z

Link: CVE-2026-50445

cve-icon Vulnrichment

Updated: 2026-07-15T16:25:29.033Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:15:04Z

Weaknesses