Windows Remote Desktop Client Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-58539Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

An out-of-bounds read vulnerability in Windows Remote Desktop Client allows an attacker to read memory on a remote system over the network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Exploitation requires network access to the RDP port and no user credentials. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker can view sensitive information from a Windows system running Remote Desktop Client by sending specially crafted network packets. This could expose configuration data, credentials, or other data transmitted during RDP sessions.
Who's at risk
Windows system administrators and IT teams managing environments where Remote Desktop Protocol is used for remote access. Affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems that use RDP for administration or remote sessions.
How it could be exploited
An attacker on the network sends a malformed RDP protocol packet to a vulnerable Windows system. The RDP client reads memory outside its intended bounds and returns the data to the attacker, disclosing information without requiring authentication or user interaction beyond running the client.
Prerequisites
  • Network access to RDP port (typically 3389)
  • Target system must be running Windows with Remote Desktop enabled or have RDP client installed
  • No credentials required
remotely exploitableno authentication requiredlow complexityinformation disclosure only (no operational impact)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply July 2026 Windows security update to patch Remote Desktop Client
API: /api/v1/advisories/fc645113-fb51-416a-97b2-f3226c11b120

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Client Information Disclosure Vulnerability | CVSS 6.5 - OTPulse