Windows Remote Desktop Client Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-58539Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
An out-of-bounds read vulnerability in Windows Remote Desktop Client allows an attacker to read memory on a remote system over the network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Exploitation requires network access to the RDP port and no user credentials. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker can view sensitive information from a Windows system running Remote Desktop Client by sending specially crafted network packets. This could expose configuration data, credentials, or other data transmitted during RDP sessions.
Who's at risk
Windows system administrators and IT teams managing environments where Remote Desktop Protocol is used for remote access. Affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems that use RDP for administration or remote sessions.
How it could be exploited
An attacker on the network sends a malformed RDP protocol packet to a vulnerable Windows system. The RDP client reads memory outside its intended bounds and returns the data to the attacker, disclosing information without requiring authentication or user interaction beyond running the client.
Prerequisites
- Network access to RDP port (typically 3389)
- Target system must be running Windows with Remote Desktop enabled or have RDP client installed
- No credentials required
remotely exploitableno authentication requiredlow complexityinformation disclosure only (no operational impact)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply July 2026 Windows security update to patch Remote Desktop Client
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fc645113-fb51-416a-97b2-f3226c11b120Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.