Impact
An out-of-bounds read vulnerability exists in Windows Remote Desktop Services that permits a local attacker with authorized access to read memory beyond intended bounds. This information disclosure can expose sensitive data that resides in the memory of the Remote Desktop Services process. The flaw is demonstrated by CWE‑125, a classic buffer under-read condition. As a result, data that should remain protected may become visible, potentially revealing credentials, cryptographic keys, or other confidential information that resides in memory at runtime.
Affected Systems
The vulnerability affects a wide range of Microsoft Windows implementations, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, in both standard and Server Core installations. All supported CPU architectures listed (x86, x64, arm64) are impacted. Users running any of these operating systems with Remote Desktop Services enabled and an authorized user presence must recognize the potential exposure.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity vulnerability. The EPSS score is not available, so the current exploitation probability remains uncertain, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented active exploitation at the time of reporting. The attack vector is local, requiring authenticated or otherwise authorized access to the affected machine, so the risk primarily applies to systems in which users have elevated or administrative privileges and who run Remote Desktop Services. Operators should treat this exposure as moderately urgent until a patch is applied.
OpenCVE Enrichment