Impact
The vulnerability arises from the use of an uninitialized resource in the Windows Remote Desktop Protocol (RDP) client, classified as CWE‑908. An attacker who can reach a target system over a network may exploit this flaw to read sensitive data that should not be exposed, resulting in a breach of confidentiality. The flaw does not provide a path for code execution, privilege escalation, or denial of service but allows unauthorized disclosure of internal information.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; Microsoft Windows Server 2012, 2016, 2019, 2022 and 2025, including all Server Core installations. The affected binaries run on x86, x64 and ARM64 architectures as indicated by the product details.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity impact on confidentiality. The EPSS score of less than 1 % indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been actively leveraged in the wild. Based on the description, it is inferred that the attack vector would be remote through the network via the RDP service, requiring only that the attacker can reach the target on the appropriate RDP port. An attacker could exploit the flaw without needing local access, though success depends on the RDP service being enabled and accessible.
OpenCVE Enrichment