Impact
An attacker can read personal information from the Remote Desktop Web Client or Windows Admin Center because the service does not enforce proper access controls on certain data. The problem is a classic instance of the CWE‑359 Informational Disclosure, resulting in confidential data exposure to unauthorized parties.
Affected Systems
Microsoft Remote Desktop Web Client and Microsoft Windows Admin Center are affected. The flaw allows an attacker to read private personal information from these services over a network. The vulnerability does not depend on a specific version; all supported releases are impacted unless a patch is applied.
Risk and Exploitability
The CVSS score is 7.1. The EPSS figure of less than 1 % shows a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is over a network connection that utilizes RDP; an attacker would need network access to the RDP service or the Windows Admin Center interface to trigger the disclosure.
OpenCVE Enrichment