Windows Remote Desktop Client Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-50376Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Use of uninitialized resource in Windows Remote Desktop Client allows an unauthorized attacker to disclose information over a network. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across multiple versions and architectures.
What this means
What could happen
An attacker could read sensitive information from Windows memory through Remote Desktop connections without authentication, potentially exposing credentials or configuration data used in your network operations.
Who's at risk
This affects IT infrastructure operators and OT network managers who use Windows 10, Windows 11, or Windows Server (2016, 2019, 2022, 2025) systems as engineering workstations, operator interfaces, or remote access gateways. Organizations running Windows-based HMI systems, SCADA servers, or historical data workstations connected to networks accessible from untrusted segments should prioritize patching.
How it could be exploited
An attacker connects to a Windows system via Remote Desktop Protocol (RDP) and sends a crafted request that causes the RDP client or server to return uninitialized memory containing sensitive information. The attack requires network access to RDP but no valid credentials.
Prerequisites
- Network access to RDP port (default 3389)
- No authentication required
remotely exploitableno authentication requiredlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict RDP access (port 3389) at the firewall to authorized engineering workstations and remote access servers only; block RDP from untrusted network segments
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the July 2026 Windows security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Long-term hardening
0/1HARDENINGDisable RDP on systems that do not require remote access, or use VPN with MFA as the sole remote access method instead of direct RDP exposure
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/4b43341e-04f4-4f8a-9699-6d15fdf4179aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.