Description
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can read personal information from the Remote Desktop Web Client or Windows Admin Center because the service does not enforce proper access controls on certain data. The problem is a classic instance of the CWE‑359 Informational Disclosure, resulting in confidential data exposure to unauthorized parties.

Affected Systems

Microsoft Remote Desktop Web Client and Microsoft Windows Admin Center are affected. The flaw allows an attacker to read private personal information from these services over a network. The vulnerability does not depend on a specific version; all supported releases are impacted unless a patch is applied.

Risk and Exploitability

The CVSS score is 7.1. The EPSS figure of less than 1 % shows a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is over a network connection that utilizes RDP; an attacker would need network access to the RDP service or the Windows Admin Center interface to trigger the disclosure.

Generated by OpenCVE AI on July 30, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for CVE-2026-56171 as published by Microsoft
  • Restrict RDP access to trusted networks or a VPN and block inbound RDP traffic from untrusted sources
  • Enable Network‑Level Authentication for all RDP sessions and restrict administrative accounts through RBAC
  • Disable or isolate Windows Admin Center if not required for operations

Generated by OpenCVE AI on July 30, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft remote Desktop Client
Vendors & Products Microsoft remote Desktop Client

Tue, 21 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Title Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft remote Desktop Web Client
Microsoft windows Admin Center
Weaknesses CWE-359
CPEs cpe:2.3:a:microsoft:remote_desktop_web_client:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft remote Desktop Web Client
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Remote Desktop Client Remote Desktop Web Client Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-07T18:22:03.106Z

Reserved: 2026-06-19T13:53:31.989Z

Link: CVE-2026-56171

cve-icon Vulnrichment

Updated: 2026-07-21T19:21:05.360Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor