Impact
The vulnerability in the Windows Remote Desktop client stems from inadequate verification of cryptographic signatures. When the client receives data that fails proper signature checks, it can still process and expose the contents to an attacker. The result is a breach of confidentiality, allowing an unauthorized entity to read sensitive information transmitted over the network. This weakness aligns with CWE-347, which describes an improper treatment of secret values due to insufficient source authenticity checks.
Affected Systems
Microsoft Remote Desktop client for Windows Desktop is affected. All installed versions of the client on Windows are potentially vulnerable, as the issue originates from the core signature check routine and no specific version list is provided in the advisory.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. However, because the attack vector is remote over the network and the flaw permits data disclosure without local privileges, the potential impact remains significant if an attacker can reach the client. Vigilance is advised, and applying the fix quickly is recommended to mitigate the risk.
OpenCVE Enrichment