Impact
The vulnerability arises from the use of an uninitialized resource in the Windows Remote Desktop Client, which allows an unauthorized attacker to disclose information over a network. The weakness enables the attacker to gain confidential data, and it is categorized as CWE‑908, reflecting scenarios where uninitialized variables permit information leakage.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations. All affected systems run the Windows Remote Desktop Client component.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based, where an attacker initiates an RDP session (or attempts a connection) from an unauthorized host to trigger the uninitialized resource and capture sensitive information. Exploitation would require network connectivity to the target machine and typically no elevated privileges on the victim.
OpenCVE Enrichment