Windows Remote Desktop Client Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-58546Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Use of uninitialized resource in Windows RDP client allows an attacker to disclose information over a network. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker could trick a user into connecting to a malicious RDP server to steal sensitive information from the user's system. This is an information disclosure risk, not a risk to operational plant control systems.
Who's at risk
Windows system administrators managing Windows 10, Windows 11, and Windows Server 2016-2025 installations, particularly those that support remote access via RDP for IT support or remote management.
How it could be exploited
An attacker must craft a malicious RDP server response that exploits uninitialized memory in the Windows RDP client. When a user connects to the attacker's server, the client leaks sensitive information from memory back to the attacker.
Prerequisites
  • User must initiate an RDP connection to an attacker-controlled server
  • User interaction required (user must click to connect)
  • No credentials required from attacker
remotely exploitableuser interaction requiredlow EPSS score (0.5%)information disclosure only
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul Windows security update to all Windows 10, Windows 11, and Windows Server systems
API: /api/v1/advisories/db4b303a-cfc3-41eb-ab01-2f84273a86b9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Client Information Disclosure Vulnerability | CVSS 6.5 - OTPulse