AI description
CVE-2026-45639 is an information disclosure vulnerability affecting the Windows Remote Desktop Protocol (RDP). This flaw stems from an out-of-bounds read condition within the RDP stack. An unauthenticated attacker can exploit this vulnerability remotely over the network without user interaction to read portions of process memory. Successful exploitation could potentially leak sensitive data such as credentials, session tokens, or protocol state data, depending on the contents of the targeted memory region. This vulnerability impacts a wide range of Windows client and server releases where RDP is available, including various versions of Windows 10, Windows 11, and Windows Server. Microsoft addressed CVE-2026-45639 as part of its security updates released on June 9, 2026.
- Description
- Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- remote_desktop_client, windows_app, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- secure@microsoft.com
- CWE-125
- Hype score
- Not currently trending
CVE-2026-45639: Windows RDP Flaw Exposes Process Memory https://t.co/17Xd53ZfiY #Cyberupdates #Cybertechnews #Cybersecurity
@cybrsecpath
13 Jun 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-45639: Windows RDP Flaw Exposes Process Memory https://t.co/17Xd53ZfiY #Cybertrending #Cybernewsdaily #Cybersecurity
@cybrsecpath
13 Jun 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s security updates released June 9, 2026 patches out-of-bounds reads in the RDP stack of CVE-2026-42908 and CVE-2026-45639 #ITSecurity
@seaarepea
10 Jun 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windowsのリモートデスクトッププロトコル(RDP)に、情報漏えいにつながる脆弱性CVE-2026-42908およびCVE-2026-45639が見つかり、Microsoftが2026年6月9日のセキュリティ更新で修正した。 いずれも認証不要でネットワー
@yousukezan
10 Jun 2026
4413 Impressions
7 Retweets
33 Likes
14 Bookmarks
0 Replies
3 Quotes
⚠️ Windows RDP Vulnerabilities Allow Attacker to Expose Sensitive Data Source: https://t.co/o3yYiODgjC Windows systems are impacted by two new Remote Desktop Protocol (RDP) information disclosure vulnerabilities, CVE-2026-42908 and CVE-2026-45639. Both issues were resolve
@The_Cyber_News
10 Jun 2026
7693 Impressions
52 Retweets
179 Likes
54 Bookmarks
6 Replies
3 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:remote_desktop_client:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "A0FB39F5-3DF4-4EB0-B095-41DEB29C7A06",
"versionEndExcluding": "1.2.7214",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:windows_app:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "1E45C1A8-0420-4618-B0B7-47BF62308231",
"versionEndExcluding": "2.0.1193.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "039BC4EF-6E49-4A8C-B1A4-BFAD9F24EC01",
"versionEndExcluding": "10.0.14393.9234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "2221A0A5-45F3-4903-943A-19E7AA69496B",
"versionEndExcluding": "10.0.14393.9234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "03A4C97D-FE89-4367-9A0E-E4E65BD49E18",
"versionEndExcluding": "10.0.17763.8880",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "FE809AA0-E917-495F-BB11-59215F47E14F",
"versionEndExcluding": "10.0.17763.8880",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "3E87DD4E-44FC-4B9A-99AB-D1DB3C67EF79",
"versionEndExcluding": "10.0.19044.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "A21A9BC4-DE4F-46BE-944F-AD6CAA92BF32",
"versionEndExcluding": "10.0.19044.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "911336E9-FAEA-4EB5-96D7-8049AE622C61",
"versionEndExcluding": "10.0.19044.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "B8BB8399-35C5-4654-A679-5E105773615B",
"versionEndExcluding": "10.0.19045.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "55571EDC-8323-4BAE-B363-113ACEF55CB2",
"versionEndExcluding": "10.0.19045.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "D14AC77E-34F3-4704-A068-D9020FF60A8C",
"versionEndExcluding": "10.0.19045.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "92508776-88BE-4872-99DB-1F690F71ADEF",
"versionEndExcluding": "10.0.22631.7219",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "410079AC-180E-4D7F-B7F6-784E36FEA036",
"versionEndExcluding": "10.0.22631.7219",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "32DB4863-6880-40B4-8EC1-9E0F40E81D7F",
"versionEndExcluding": "10.0.26100.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E691C9E5-5271-436D-A7FD-C25BEA4D447D",
"versionEndExcluding": "10.0.26100.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "1D3DEE4A-9959-4716-BC39-35660AC22BC4",
"versionEndExcluding": "10.0.26200.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "1000C085-A5D7-4027-B9C1-6AE7DA468FB7",
"versionEndExcluding": "10.0.26200.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9C7AD7ED-307B-40B9-B706-45FB178C36D8",
"versionEndExcluding": "10.0.28000.2269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "8967AF79-CAD0-4F87-85A5-95D031C9FEFA",
"versionEndExcluding": "10.0.28000.2269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:-:*:x64:*",
"matchCriteriaId": "EC82C3C4-FCA5-4883-9B14-F5CD18666182",
"versionEndExcluding": "10.0.14393.9234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:-:*:x64:*",
"matchCriteriaId": "4722A8F2-4CA7-4893-940B-7484C47F5352",
"versionEndExcluding": "10.0.17763.8880",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:-:*:x64:*",
"matchCriteriaId": "CFA40C1D-0857-4B9A-92CB-5666E35062F2",
"versionEndExcluding": "10.0.20348.5256",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E127A6E6-C261-4039-8A13-A2FAC4606573",
"versionEndExcluding": "10.0.26100.32995",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]