Windows Remote Desktop Client Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-61918Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
An out-of-bounds read vulnerability in Windows Remote Desktop Client allows an unauthenticated attacker to disclose sensitive information from memory on affected systems. The flaw is triggered by sending specially crafted network packets to the RDP protocol handler, potentially exposing credentials, configuration details, or other data without requiring valid user interaction or system credentials. Exploitation likelihood is assessed as less likely.
What this means
What could happen
An attacker can view sensitive information from memory on a Windows machine running Remote Desktop Client by sending specially crafted network packets. This could expose credentials, configuration data, or other sensitive details stored in the RDC process memory.
Who's at risk
Windows IT and facility teams managing Remote Desktop Client installations, particularly those operating engineering workstations, SCADA servers, or administrative systems that connect to building automation or process control systems. Affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across all architectures.
How it could be exploited
An attacker sends a malformed RDP protocol packet to a Windows system with Remote Desktop Client running. The out-of-bounds memory read flaw allows the attacker to retrieve data from memory that should not be accessible, potentially exfiltrating this information over the network without needing valid credentials.
Prerequisites
- Network access to the target Windows system on the RDP port (typically 3389 or alternate configured port)
- Remote Desktop Client must be running on the target system
- No authentication required—the flaw exists in pre-authentication protocol handling
remotely exploitableno authentication requiredlow complexityinformation disclosure (not immediate operational impact)
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to RDP ports (default 3389) to only authorized administrative systems using firewall rules
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Microsoft security update to your Windows systems (or latest cumulative update for your OS version)
HARDENINGDisable Remote Desktop services on systems that do not require remote access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ab16446b-0b53-4df4-9668-fae983ba5f97Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.