Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-50445Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A buffer over-read vulnerability in Windows Remote Desktop Protocol (RDP) allows an unauthenticated attacker to read sensitive memory contents from a system over the network. The flaw affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025). Exploitation requires user interaction and RDP to be enabled and network-accessible. Vendors have released patches for all affected versions.

What this means
What could happen
An attacker can read memory contents from a Windows system via Remote Desktop Protocol, potentially exposing sensitive data like passwords, encryption keys, or process information without needing valid credentials.
Who's at risk
Windows IT administrators and OT staff operating workstations or servers (Windows 10, 11, Server 2016, 2019, 2022, 2025) with RDP enabled. This affects both administrative engineering workstations and any Windows-based HMI, supervisory, or server infrastructure that relies on Remote Desktop for remote access or management.
How it could be exploited
An attacker sends a specially crafted RDP connection request to a Windows system with RDP enabled. The buffer over-read flaw allows the attacker to read memory beyond the intended buffer, disclosing sensitive information back over the network. User interaction is required (user must be viewing a display that triggers the vulnerability).
Prerequisites
  • RDP service must be enabled and reachable from the attacker's network (port 3389 by default)
  • User interaction required - a user must be actively using RDP or viewing the desktop when the malicious connection is made
remotely exploitableno authentication requiredlow complexityaffects sensitive data disclosure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict RDP access (port 3389) to only trusted networks and IP addresses using firewall rules or network segmentation
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply July 2026 Windows security update for your Windows version (10/11/Server 2016/2019/2022/2025)
Long-term hardening
0/1
HARDENINGDisable RDP on systems that do not require remote desktop access
API: /api/v1/advisories/84927e47-4f93-4fc4-87a4-6df111b6362f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.