Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-50445Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
A buffer over-read vulnerability in Windows Remote Desktop Protocol (RDP) allows an unauthenticated attacker to read sensitive memory contents from a system over the network. The flaw affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025). Exploitation requires user interaction and RDP to be enabled and network-accessible. Vendors have released patches for all affected versions.
What this means
What could happen
An attacker can read memory contents from a Windows system via Remote Desktop Protocol, potentially exposing sensitive data like passwords, encryption keys, or process information without needing valid credentials.
Who's at risk
Windows IT administrators and OT staff operating workstations or servers (Windows 10, 11, Server 2016, 2019, 2022, 2025) with RDP enabled. This affects both administrative engineering workstations and any Windows-based HMI, supervisory, or server infrastructure that relies on Remote Desktop for remote access or management.
How it could be exploited
An attacker sends a specially crafted RDP connection request to a Windows system with RDP enabled. The buffer over-read flaw allows the attacker to read memory beyond the intended buffer, disclosing sensitive information back over the network. User interaction is required (user must be viewing a display that triggers the vulnerability).
Prerequisites
- RDP service must be enabled and reachable from the attacker's network (port 3389 by default)
- User interaction required - a user must be actively using RDP or viewing the desktop when the malicious connection is made
remotely exploitableno authentication requiredlow complexityaffects sensitive data disclosure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict RDP access (port 3389) to only trusted networks and IP addresses using firewall rules or network segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply July 2026 Windows security update for your Windows version (10/11/Server 2016/2019/2022/2025)
Long-term hardening
0/1HARDENINGDisable RDP on systems that do not require remote desktop access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/84927e47-4f93-4fc4-87a4-6df111b6362fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.