Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-54126Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

An out-of-bounds read vulnerability in Windows RDP allows an unauthenticated attacker on the network to disclose sensitive information from system memory by sending a specially crafted RDP connection request. Affected versions include Windows 10 (all supported versions), Windows 11 (all supported versions), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected platforms as part of the July 2026 security update.

What this means
What could happen
An attacker on the network could read sensitive memory data from Windows systems running RDP without authentication, potentially exposing credentials, session keys, or other confidential information stored in RAM.
Who's at risk
This affects IT administrators and OT teams running Windows servers for industrial workstations, historian servers, or HMI systems. Windows 10 and Windows Server 2016–2025 systems used for remote access to control systems are at risk.
How it could be exploited
An attacker sends a specially crafted RDP connection request to port 3389. The RDP service processes the malformed data and reads beyond allocated memory boundaries, leaking sensitive information back to the attacker without requiring valid credentials or user interaction.
Prerequisites
  • Network access to RDP port 3389 on the target system
  • RDP service enabled and listening (default on Windows servers)
remotely exploitableno authentication requiredlow complexityaffects remote access to control systems
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDRestrict RDP access (port 3389) to authorized management networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft July 2026 security update to all affected Windows 10, Windows 11, and Windows Server systems
API: /api/v1/advisories/08363df4-9297-4597-a951-3bdca1467e1c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.