Impact
An out‑of‑bounds read in the Windows Remote Desktop Client enables an attacker who can reach the client over the network to read unintended memory, thereby disclosing sensitive data. The flaw originates from CWE‑125 and results in a direct information disclosure that may reveal credentials, configuration data, or other confidential information.
Affected Systems
Microsoft Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, all common 64‑bit and, for selected Windows 10/11 releases, 32‑bit or ARM64 architectures.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1 % implies a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw over the Remote Desktop Protocol without local privileges by sending crafted traffic to the client, allowing unintended memory reads and thus information disclosure.
OpenCVE Enrichment