Impact
Use of an uninitialized resource in the Windows Remote Desktop Protocol client permits an attacker to read sensitive data over a network. The vulnerability arises from improper handling of memory that results in unintended disclosure of information, thereby compromising confidentiality. The weakness is represented by CWE‑908, indicating a failure to preserve confidentiality of allocated resources. No direct code execution or privilege escalation is possible through this flaw, but sensitive data such as user credentials or configuration details could be exposed to a network adversary.
Affected Systems
The flaw affects Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2, Windows 11 releases 24H2, 25H2, and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all core installations. These are the products listed in the CNA vendor/product dossier and are susceptible to the uninitialized resource issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk, while the EPSS score of less than 1% suggests that exploitation at the current time is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be able to send Remote Desktop traffic to the vulnerable machine to trigger the flaw; local privileges or code execution are not required. Network attackers who can reach the target on the RDP port may request the client, causing it to reveal inadvertent memory contents to them.
OpenCVE Enrichment