Windows Remote Desktop Client Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-58533Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
A flaw in Windows Remote Desktop Client allows an unauthenticated network attacker to read uninitialized memory and disclose sensitive information. The vulnerability exists due to improper handling of uninitialized resources in the RDP protocol handler.
What this means
What could happen
An attacker could read sensitive information from Windows Remote Desktop Client memory, potentially exposing credentials, session data, or other confidential details transmitted during RDP connections. This information disclosure occurs without authentication required.
Who's at risk
Organizations using Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, or 2025 should evaluate their RDP exposure. This affects any IT administrator workstations, servers, and jump hosts that use Remote Desktop for system administration or remote support.
How it could be exploited
An attacker on the network can send specially crafted packets to a Windows system running Remote Desktop Client to trigger uninitialized memory disclosure. The attacker does not need valid credentials or user interaction to read the leaked information.
Prerequisites
- Network access to the RDP-enabled system
- RDP service listening on the network (typically port 3389)
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects sensitive data (credentials, session data)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to RDP port 3389 at the firewall to only authorized administrative networks and jump-box systems
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply Windows security updates for July 2026 or later to all Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Long-term hardening
0/1HARDENINGDisable Remote Desktop Client on systems that do not require remote access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5cdd582f-5da5-458f-8bc4-66ed02739bc7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.