Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-55003Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

An uninitialized resource in Windows Remote Desktop Protocol (RDP) allows an unauthorized attacker to disclose sensitive information over a network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. An attacker with network access to the RDP port can trigger memory information disclosure without providing valid credentials.

What this means
What could happen
An attacker who connects to a Windows machine with RDP enabled could read sensitive memory information from the RDP service, potentially revealing credentials, encryption keys, or other confidential data without authentication. This creates a risk of lateral movement or further compromise.
Who's at risk
IT staff and network administrators managing Windows servers and workstations. This particularly affects water utilities and electric utilities that use Windows servers for SCADA historian systems, HMI platforms (like those running on Windows Server 2019/2022), and administrative workstations that may access industrial control systems. Any Windows 10 or Windows Server machine with RDP enabled and connected to a network is potentially affected.
How it could be exploited
An attacker needs network access to the RDP port (typically 3389) on an affected Windows machine. They send a specially crafted RDP connection request that triggers an uninitialized memory read in the RDP service, allowing them to extract sensitive data from memory without providing valid credentials.
Prerequisites
  • Network access to RDP port (3389) on the target machine
  • RDP service enabled on the target Windows system
  • Target running one of the affected Windows versions
Remotely exploitableNo authentication requiredLow complexity attackMemory information disclosureCould lead to credential theft
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict RDP access at the firewall to only authorized administrative networks or jump servers
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the July 2026 Windows security update to all affected machines (Windows 10, Windows 11, Windows Server 2016, 2019, 2022, 2025)
Long-term hardening
0/2
HARDENINGDisable RDP on machines that do not require remote administration
HARDENINGImplement network segmentation to isolate management networks from operational technology networks
API: /api/v1/advisories/60c2de0a-99e6-4501-8fa3-62af88d3c2d9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.