Impact
An uninitialized resource in the Windows Remote Desktop Protocol stack enables an attacker to introduce malformed data that corrupts memory, giving the attacker the ability to execute arbitrary code on the target system. The flaw is classed as CWE-908, reflecting improper use of an uninitialized resource that can lead to unexpected behavior. Because code execution can be achieved, an adversary who can reach the Remote Desktop service could potentially gain full control of the affected machine.
Affected Systems
Affected Systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases from 2012 through 2025, covering both standard and Server Core installations for each server edition.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical, while the EPSS score of less than 1% indicates a low current probability of exploitation. The flaw is not listed in the CISA KEV catalog. An attacker would most likely trigger the vulnerability by sending specially crafted RDP traffic, typically over the default service port 3389—this is inferred from the nature of Remote Desktop. The only definitive mitigation is the vendor‑supplied update that addresses CVE‑2026‑56190; without it, the system remains exposed to remote code execution.
OpenCVE Enrichment