Impact
A buffer over-read in the Windows Remote Desktop Protocol (RDP) allows an unauthorized actor to read portions of memory that the RDP service should not expose, potentially revealing sensitive system or user data. This flaw is a classic example of CWE‑126, where improper bounds checking exposes confidential information. The resulting impact is a loss of confidentiality and the risk that critical data could be accessed by an attacker with no legitimate rights.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including core installations. The vulnerability affects both x86 and x64 architectures, as well as ARM‑based builds for the listed Windows 11 releases.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity classification. With an EPSS score of less than 1%, the likelihood of exploitation at this time is low, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation occurs over the RDP service, requiring an attacker to reach the RDP port on the target machine; authentication is not indicated in the description, implying that the attack may be performed without user credentials. The likely attack vector is therefore remote network access to port 3389. The threat is chiefly a data‑disclosure risk rather than a privilege‑escalation or denial‑of‑service attack.
OpenCVE Enrichment