Impact
The Remote Desktop Client contains an out-of-bounds read that can be triggered by an authorized attacker to expose sensitive information to a remote host. This read vulnerability is classified as an informational disclosure flaw, allowing an attacker to read memory beyond the intended bounds and gather data that may include credentials, configuration details, or other confidential material. The flaw is identified by CWE‑125 and can lead to partial disclosure of insider data or system secrets when exploited in a trusted network environment.
Affected Systems
Affected systems include Microsoft Windows 10 and Windows 11 desktop clients from version 1607 through 26H1, as well as Windows Server 2012 through the upcoming 2025 release, covering both standard and server‑core installations. All listed builds are impacted, including the recent 23H2, 24H2, 25H2, and 26H1 releases on x64, arm64, and x86 platforms.
Risk and Exploitability
The CVSS score is 5.7, indicating a moderate risk. EPSS is not published, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. However, because the issue requires an attacker to be already authenticated to the Remote Desktop session, the window of opportunity is bounded by existing RDP access policies. Organizations should treat this as a moderate risk and check for the latest Microsoft patch. In the absence of an official fix, effective mitigation involves limiting RDP exposure, enforcing least privilege, and monitoring session activity.
OpenCVE Enrichment