Windows Remote Desktop Services Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-69616Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in Windows Remote Desktop Services allows a local user to disclose sensitive information. The vulnerability requires local access to the system and could expose confidential data from system memory. Microsoft has released security patches for all affected Windows versions.
What this means
What could happen
An attacker with local access to a Windows system running Remote Desktop Services could read sensitive data from system memory that they shouldn't have access to. This could expose credentials, configuration details, or other confidential information used by the RDS system.
Who's at risk
Windows system administrators and OT environments using Windows servers for remote access, engineering workstations, or server-based industrial control components. Specifically affects Windows 10 (all recent versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025 systems with Remote Desktop Services enabled.
How it could be exploited
An attacker must first gain local user-level access to a Windows system with Remote Desktop Services enabled. From there, they can trigger an out-of-bounds read in the RDS component to access memory regions outside the intended bounds, disclosing sensitive information that was not intended to be accessible to their privilege level.
Prerequisites
- Local user-level account on the affected Windows system
- Remote Desktop Services component enabled and running on the target system
No authentication required for local access exploitationLow complexity attackAffects information confidentiality
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXInstall Windows security update from September 2026 for your Windows version (see product fixes for specific build numbers)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/1e6299d4-422c-4618-b8fc-45f2e4f6e3a9Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.