Impact
An out‑of‑bounds read in the Windows Remote Desktop Client can be leveraged by an unauthorized attacker to reveal memory contents, potentially exposing sensitive data on the client machine. The flaw aligns with CWE‑125 and CWE‑200, meaning the vulnerability arises from improper bounds checking and leads to accidental information disclosure. It is an internal client issue that affects the confidentiality of the information stored or processed by the desktop client during a remote session.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, each with both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog, suggesting it has not yet been widely abused. Attackers would need network access to establish a Remote Desktop session with the vulnerable client; once connected, they can trigger the out‑of‑bounds read to access arbitrary memory contents without requiring elevated privileges, making it a potentially useful tool for harvesting credentials or other data.
OpenCVE Enrichment