Impact
Out-of-bounds read in the Windows Remote Desktop Protocol handling allows an attacker who can send crafted packets to a target to read memory contents and disclose that information over the network, resulting in confidential data leakage without elevation of privileges.
Affected Systems
10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. The flaw exists across both 32‑bit and 64‑bit architectures as indicated by the affected CPE entries.
Risk and Exploitability
With a CVSS score of 6.5, the issue presents a moderate severity level. The EPSS score of less than 1% suggests a low likelihood of mass exploitation at present, and it is not listed in the KEV catalog. The attack vector is inferred to be remote; an unauthenticated attacker must be able to reach the Remote Desktop service on the target machine, craft appropriate protocol packets, and read the resulting memory dump. Once exploited, attackers can obtain sensitive data that resides in the victim's memory. No confirmed workaround is documented beyond restricting RDP exposure.
OpenCVE Enrichment