Impact
The flaw exists because an uninitialized resource is used in the Windows Remote Desktop Protocol stack. An attacker who gains authorized RDP access can trigger the flaw, resulting in the transmission of sensitive data over the network. This vulnerability corresponds to the disclosure of confidential information without providing code execution or privilege escalation.
Affected Systems
The issue affects multiple Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server releases from 2012 through 2025, both full and Server Core installations.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is considered moderate and poses a confidentiality risk. The EPSS score indicates low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack requires an existing RDP session and exploits the RDP network traffic. It is inferred that no elevated privileges are needed beyond those required for a normal RDP session, and it is inferred that the attack vector is network‑based.
OpenCVE Enrichment