Windows Remote Desktop Client Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-61924Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

An out-of-bounds read vulnerability in the Windows Remote Desktop Client allows an attacker to disclose sensitive information over the network. An attacker controlling or intercepting an RDP server can craft responses that trigger the vulnerability, leaking memory contents from the client machine. The vulnerability affects all supported versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker could craft a malicious RDP server response that causes an out-of-bounds read in the Windows Remote Desktop Client, exposing sensitive information such as memory contents from the client machine. This could leak credentials, encryption keys, or other confidential data.
Who's at risk
Windows IT administrators and OT staff who use Remote Desktop Client to connect to control systems, SCADA servers, or engineering workstations. This affects Windows 10 and Windows 11 users across all supported versions, as well as Windows Server 2016, 2019, 2022, and 2025. Anyone using RDP for remote system management should apply the fix.
How it could be exploited
An attacker would need to intercept or respond to an RDP connection from a victim's Windows machine. When the victim connects to a malicious or compromised RDP server, the attacker's crafted response triggers the out-of-bounds read vulnerability, allowing the attacker to leak memory contents from the client.
Prerequisites
  • Network connectivity to the Windows machine's RDP client
  • Victim must initiate an RDP connection to an attacker-controlled or compromised RDP server
  • No authentication or special privileges required on the victim's machine
remotely exploitableno authentication requiredlow complexityinformation disclosure risk
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 Windows security update for your version of Windows (see product fixes for specific build numbers)
Long-term hardening
0/2
HARDENINGRestrict RDP client usage to trusted networks and disable RDP if not required
HARDENINGRequire RDP connections only to known, trusted servers and disable connections to untrusted hosts
API: /api/v1/advisories/478ad6b8-4c52-4f5b-997e-ddbb35e03623

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.