Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-50497Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
An off-by-one error in Windows Remote Desktop Protocol allows an unauthenticated attacker to disclose information from RDP session memory. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Exploitation is assessed as unlikely but possible over the network without user interaction.
What this means
What could happen
An attacker could view sensitive information from RDP sessions without authentication, such as credentials or process data displayed on remote workstations or servers. This could compromise operational security if RDP is used to manage SCADA, HMI, or engineering workstations in your utility.
Who's at risk
Windows workstations and servers used for remote administration of utility infrastructure. Primary concern is engineering workstations, HMI systems, and administrative servers that rely on RDP for SCADA access or process control management.
How it could be exploited
An attacker on the network sends specially crafted RDP protocol messages to trigger an off-by-one buffer read, leaking information from RDP session memory without needing to authenticate or interact with the user.
Prerequisites
- Network access to RDP listening port (typically 3389)
- RDP service enabled on target system
- No user interaction required
remotely exploitableno authentication requiredlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Do now
0/1WORKAROUNDRestrict RDP access via firewall to authorized engineering workstations and administrative networks only
Schedule — requires maintenance window
0/7Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 (all versions) to the corresponding patched build
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/41917953-1fe6-46c8-b795-c04b5bd7a0b0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.