CVE-2026-70587
massImproper null termination (info disclosure) in Microsoft Windows Remote Desktop Protocol
CVE-2026-70587 is an improper null termination flaw (CWE-170) in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. A remote, unauthenticated attacker can trigger the flaw by sending crafted network input to a system's RDP listener, causing the service to mishandle string termination and leak information to the attacker. The impact is limited to confidential disclosure — there is no integrity or availability impact per the CVSS vector — but the flaw requires no privileges, no user interaction, and is easy to exploit (AV:N/AC:L/PR:N/UI:N). It affects Windows systems with the RDP service reachable over a network, which is most concerning for endpoints and servers with RDP exposed to the internet or shared networks. As of now there is no known public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS assigns a 0.8% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for this CVE as soon as it is available, prioritizing systems where RDP is reachable from untrusted networks. In the meantime, inventory internet-facing RDP (TCP 3389), restrict access via firewall/VPN rules, and keep Network-Level Authentication enforced; monitor for published proof-of-concept code given the unauthenticated, network-reachable nature of the flaw.
| Microsoft Windows Remote Desktop Protocol (RDP) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-170
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.