Impact
The vulnerability is an improper null termination in the Windows Remote Desktop Protocol component. An attacker who can initiate an RDP session without authentication can observe sensitive data that should not be exposed. This results in the disclosure of confidential information that may include user credentials or memory contents, potentially compromising confidentiality. This weakness corresponds to improper null termination (CWE‑170).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, and the corresponding Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high risk level. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of authentication required for exploitation and the fact that RDP is a widely used network service increases the likelihood that attackers may target affected hosts. An adversary would need network access to port 3389 and could exploit the flaw to read data in the remote session, which could be leveraged for further compromise. This scenario represents a significant threat to confidentiality on all impacted systems.
OpenCVE Enrichment