Windows Remote Desktop Services Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-69616Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Windows Remote Desktop Services allows a local user to disclose sensitive information. The vulnerability requires local access to the system and could expose confidential data from system memory. Microsoft has released security patches for all affected Windows versions.

What this means
What could happen
An attacker with local access to a Windows system running Remote Desktop Services could read sensitive data from system memory that they shouldn't have access to. This could expose credentials, configuration details, or other confidential information used by the RDS system.
Who's at risk
Windows system administrators and OT environments using Windows servers for remote access, engineering workstations, or server-based industrial control components. Specifically affects Windows 10 (all recent versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025 systems with Remote Desktop Services enabled.
How it could be exploited
An attacker must first gain local user-level access to a Windows system with Remote Desktop Services enabled. From there, they can trigger an out-of-bounds read in the RDS component to access memory regions outside the intended bounds, disclosing sensitive information that was not intended to be accessible to their privilege level.
Prerequisites
  • Local user-level account on the affected Windows system
  • Remote Desktop Services component enabled and running on the target system
No authentication required for local access exploitationLow complexity attackAffects information confidentiality
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXInstall Windows security update from September 2026 for your Windows version (see product fixes for specific build numbers)
API: /api/v1/advisories/1e6299d4-422c-4618-b8fc-45f2e4f6e3a9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Services Information Disclosure Vulnerability | CVSS 5.5 - OTPulse