Impact
An out-of-bounds read occurs in the Windows Remote Desktop Protocol (RDP) implementation. The flaw allows an attacker who is not authenticated to read memory contents that the service should not expose, resulting in the disclosure of sensitive data. The vulnerability is a classic example of CWE‑125, where improper bounds checking leads to confidentiality compromise.
Affected Systems
The affected products are Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2 and Windows 11 releases 24H2, 25H2, 26H1, along with Windows Server 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog, meaning no publicly disclosed exploits are known. Based on the description, the attack likely requires the attacker to be able to connect to the victim’s RDP service over the network and send a specially crafted packet that triggers the out-of-bounds read. No privileged local access is required; the flaw is exploitable remotely by any network attacker with RDP reach.
OpenCVE Enrichment