Windows Remote Desktop Client Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-58535Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
A use of uninitialized resource in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose sensitive information over the network. The vulnerability affects Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025 across multiple versions and architectures.
What this means
What could happen
An attacker could intercept or access sensitive information transmitted via Windows RDP connections, such as credentials or session data. This could lead to unauthorized access to remote systems or exposure of confidential operational data.
Who's at risk
Windows IT administrators and OT engineers who use Remote Desktop Protocol to manage servers and workstations, particularly in environments running Windows 10, Windows 11, or Windows Server 2016–2025. This affects remote management infrastructure in utilities and municipalities that rely on RDP for system administration.
How it could be exploited
An attacker on the network sends a specially crafted RDP connection request to a vulnerable Windows system. The uninitialized resource in the RDP protocol handler leaks sensitive information in the response, which the attacker captures without needing to authenticate.
Prerequisites
- Network access to port 3389 (RDP)
- Target system running an affected Windows version
- No credentials required
- User interaction may be required to initiate RDP connection
remotely exploitableno authentication requiredlow complexityinformation disclosure risk
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to port 3389 (RDP) from untrusted networks using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jul security update to Windows 10, Windows 11, or Windows Server systems
Long-term hardening
0/1HARDENINGDisable RDP service on systems that do not require remote desktop connectivity
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/53965232-7c90-43df-91fe-ee2de34c9ebdGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.