ZeroHour

CVE-2026-57098

mass

Information Disclosure via Improper Signature Verification in Windows RDP Client

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-57098 is an improper verification of cryptographic signature flaw (CWE-347) in the Windows RDP Client, allowing an unauthorized attacker to disclose information over a network. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) indicates exploitation requires no privileges or user interaction and yields high confidentiality impact with no integrity or availability impact, most plausibly triggered when the client accepts improperly signed data from a malicious or man-in-the-middle RDP endpoint. An attacker who successfully exploits it gains access to confidential information handled by the RDP client session. Anyone running the Windows RDP Client — effectively any Windows installation used to initiate RDP connections — is affected. Exploitation has not been observed: EPSS estimates only a 0.6% probability of exploitation in the next 30 days (48th percentile), the flaw is not in CISA's KEV catalog, and no public proof-of-concept is known.

What to do: Check Microsoft's advisory and Windows Update for the patched RDP client build for your Windows version and deploy it through your standard patching channel, prioritizing endpoints that routinely connect to external or untrusted RDP servers. Until patched, restrict RDP client use to trusted, authenticated endpoints and treat man-in-the-middle exposure (untrusted networks, unverified gateways) as the primary attack path. No workarounds, public PoCs, or in-the-wild exploitation are documented yet, so monitor the Microsoft advisory for updates.

Affected
Microsoft Windows RDP Client
Estimated exposure
mass≈1 billion+ installations (the RDP client ships with effectively every Windows desktop and server) — The vulnerable component is the built-in Windows RDP client (mstsc) present on virtually all Windows endpoints in enterprise and consumer deployments, so realistic exposure is on the order of hundreds of millions to over a billion systems,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.