Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Plan PatchCVSS 7.5CVE-2026-42908Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Windows Remote Desktop Protocol (RDP) allows an attacker to disclose sensitive information over the network. The vulnerability requires network access to RDP services but no authentication or user interaction. It affects Windows 10, Windows 11, and Windows Server 2016 through 2025.

What this means
What could happen
An attacker could read sensitive data from memory on systems running RDP services, potentially exposing credentials, encryption keys, or process information that could be used in further attacks.
Who's at risk
IT and OT administrators managing Windows-based remote access and industrial workstations. This affects organizations using Windows servers (2016, 2019, 2022, 2025) or Windows 10/11 clients for remote administration of control systems, SCADA workstations, historian servers, or engineering terminals. Water utilities and municipal electric companies using Windows servers for historian systems, HMI platforms, or remote facility access are at risk.
How it could be exploited
An attacker with network access to port 3389 (RDP) could send specially crafted packets to the RDP service, triggering an out-of-bounds read and extracting information from system memory without needing to authenticate or interact with a user.
Prerequisites
  • Network access to TCP port 3389 (RDP service)
  • Windows system with RDP enabled and exposed to the network
remotely exploitableno authentication requiredlow complexityhigh CVSS score (7.5)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict RDP access (port 3389) to authorized administrative systems only using firewall rules
WORKAROUNDDisable RDP on systems that do not require it
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the June 2026 security update from Microsoft that includes the RDP out-of-bounds read fix
Long-term hardening
0/1
HARDENINGUse VPN or jump hosts for remote administration of critical servers instead of exposing RDP directly to the network
API: /api/v1/advisories/546e7bf3-d35b-470d-aa03-4fe109ef11b6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | CVSS 7.5 - OTPulse