Windows Remote Desktop Client Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-61924Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
An out-of-bounds read vulnerability in the Windows Remote Desktop Client allows an attacker to disclose sensitive information over the network. An attacker controlling or intercepting an RDP server can craft responses that trigger the vulnerability, leaking memory contents from the client machine. The vulnerability affects all supported versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An attacker could craft a malicious RDP server response that causes an out-of-bounds read in the Windows Remote Desktop Client, exposing sensitive information such as memory contents from the client machine. This could leak credentials, encryption keys, or other confidential data.
Who's at risk
Windows IT administrators and OT staff who use Remote Desktop Client to connect to control systems, SCADA servers, or engineering workstations. This affects Windows 10 and Windows 11 users across all supported versions, as well as Windows Server 2016, 2019, 2022, and 2025. Anyone using RDP for remote system management should apply the fix.
How it could be exploited
An attacker would need to intercept or respond to an RDP connection from a victim's Windows machine. When the victim connects to a malicious or compromised RDP server, the attacker's crafted response triggers the out-of-bounds read vulnerability, allowing the attacker to leak memory contents from the client.
Prerequisites
- Network connectivity to the Windows machine's RDP client
- Victim must initiate an RDP connection to an attacker-controlled or compromised RDP server
- No authentication or special privileges required on the victim's machine
remotely exploitableno authentication requiredlow complexityinformation disclosure risk
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Windows security update for your version of Windows (see product fixes for specific build numbers)
Long-term hardening
0/2HARDENINGRestrict RDP client usage to trusted networks and disable RDP if not required
HARDENINGRequire RDP connections only to known, trusted servers and disable connections to untrusted hosts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/478ad6b8-4c52-4f5b-997e-ddbb35e03623Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.