ZeroHour

CVE-2026-70587

mass

Improper null termination (info disclosure) in Microsoft Windows Remote Desktop Protocol

CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
AI analysis

CVE-2026-70587 is an improper null termination flaw (CWE-170) in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. A remote, unauthenticated attacker can trigger the flaw by sending crafted network input to a system's RDP listener, causing the service to mishandle string termination and leak information to the attacker. The impact is limited to confidential disclosure — there is no integrity or availability impact per the CVSS vector — but the flaw requires no privileges, no user interaction, and is easy to exploit (AV:N/AC:L/PR:N/UI:N). It affects Windows systems with the RDP service reachable over a network, which is most concerning for endpoints and servers with RDP exposed to the internet or shared networks. As of now there is no known public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS assigns a 0.8% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for this CVE as soon as it is available, prioritizing systems where RDP is reachable from untrusted networks. In the meantime, inventory internet-facing RDP (TCP 3389), restrict access via firewall/VPN rules, and keep Network-Level Authentication enforced; monitor for published proof-of-concept code given the unauthenticated, network-reachable nature of the flaw.

Affected
Microsoft Windows Remote Desktop Protocol (RDP)
Estimated exposure
mass≈hundreds of thousands of internet-exposed RDP endpoints, plus a far larger installed base of LAN-reachable Windows hosts — Public internet-wide scans (e.g., Shodan/Censys) regularly enumerate on the order of 10^5–10^6 hosts with RDP/3389 reachable, and RDP is enabled by default on many Windows deployments, so well over 100k exposed systems is plausible.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-170
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.