Windows Remote Desktop Client Information Disclosure Vulnerability

MonitorCVSS 5.7CVE-2026-69317Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.

What this means
What could happen
An attacker with valid credentials who connects via Remote Desktop could read sensitive data from the server's memory, potentially exposing configuration details, credentials, or operational information.
Who's at risk
IT and network administrators who manage Windows desktops and servers using Remote Desktop Protocol for remote administration. This affects Windows 10 and 11 workstations as well as Windows Server 2016, 2019, 2022, and 2025 systems used for centralized management or remote access.
How it could be exploited
An attacker with valid Remote Desktop Protocol (RDP) credentials connects to an affected Windows system and exploits an out-of-bounds memory read in the RDP client to access data outside the intended memory region, allowing information disclosure.
Prerequisites
  • Valid Remote Desktop Protocol credentials (username and password)
  • Network access to RDP port 3389 or configured alternative port
  • Affected Windows operating system running Remote Desktop Client
requires authenticationremotely exploitablelow complexity exploitationinformation disclosure impact
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to RDP port 3389 to only authorized administrative hosts and jump servers using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft September 2026 security update to bring Windows systems to the specified patched build number for your version (e.g., Build 10.0.19045.7725 for Windows 10 Version 22H2)
Long-term hardening
0/1
HARDENINGRequire multi-factor authentication (MFA) for all Remote Desktop Protocol connections
API: /api/v1/advisories/e8a1199d-ad3e-4a6f-81f4-0f1023392e74

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Client Information Disclosure Vulnerability | CVSS 5.7 - OTPulse