Impact
The vulnerability stems from Windows RDP using an uninitialized resource, classified as CWE-908. An attacker who can reach a host’s RDP port can read sensitive data that should not be exposed, leading to a breach of confidentiality. The flaw does not allow arbitrary code execution or denial of service; its impact remains limited to disclosure of potentially private or credential information transmitted over the network.
Affected Systems
All Microsoft Windows client and server editions that support RDP and match the affected versions are impacted. This includes Windows 10 from version 1607 through 22H2, Windows 11 from 24H2 through 26H1, and Windows Server from 2012 up to 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% reflects a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote network access to the RDP service; an unauthenticated attacker can trigger the disclosure by simply connecting to the RDP port, without needing local privileges.
OpenCVE Enrichment