Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-57979Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Out-of-bounds read vulnerability in Windows Remote Desktop Protocol (RDP) allows an attacker to disclose information over a network without authentication. The vulnerability exists in RDP implementations across Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker could read sensitive data from system memory through RDP without valid credentials, potentially exposing configuration details, credentials, or operational data from HMI systems and engineering workstations that use RDP for remote access.
Who's at risk
Windows administrators managing HMI systems, SCADA workstations, and engineering workstations that rely on RDP for remote access and administration. This affects organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 with RDP enabled on systems controlling or monitoring critical infrastructure.
How it could be exploited
An attacker with network access to port 3389 (RDP) sends a specially crafted RDP packet to trigger an out-of-bounds memory read, extracting information from the target system's memory without authentication or user interaction.
Prerequisites
  • Network access to RDP port 3389 (TCP)
  • RDP service enabled on target system
remotely exploitableno authentication requiredlow complexityaffects administrative access to OT systems
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/10
Do now
0/1
WORKAROUNDRestrict RDP access (port 3389) to trusted networks and engineering workstations only using firewall rules
Schedule — requires maintenance window
0/8

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 (all installations) to Build 10.0.14393.9339 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 (all installations) to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (all installations) to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9339 or later
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 and 22H2 to Build 10.0.19044.7548 or 10.0.19045.7548 respectively
HOTFIXUpdate Windows 11 (all versions) to Build 10.0.26100.8875 or later for 24H2/25H2, or 10.0.28000.2525 for 26H1
Long-term hardening
0/1
HARDENINGDisable RDP on systems that do not require remote administration
API: /api/v1/advisories/d400466e-0996-4a19-a43f-75322e5ff710

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | CVSS 6.5 - OTPulse