CVE-2022-26940
published 2022-05-10CVE-2022-26940: Remote Desktop Protocol Client Information Disclosure Vulnerability
PriorityP333medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
2.37%
81.9th percentile
Remote Desktop Protocol Client Information Disclosure Vulnerability
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | remote_desktop_client_for_windows_desktop | >= 1.2.0.0 < 1.2.3130 | 1.2.3130 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.675 | 10.0.22000.675 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.707 | 10.0.20348.707 |
| msrc | remote_desktop_client_for_windows_desktop | — | — |
| msrc | windows_11_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Remote Desktop Protocol Client Information Disclosure Vulnerability
vendor_msrc·2022-05-10·CVSS 6.5
CVE-2022-26940 [MEDIUM] Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of initialized or uninitialized memory in the process heap.
Remote Desktop Client: Remote Desktop Client
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/windowsdesktop-whatsnew#updates-for-version-123130
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013944
Re
GHSA
GHSA-r3g9-4c8x-fwv7: Remote Desktop Protocol Client Information Disclosure Vulnerability
ghsa_unreviewed·2022-05-11
CVE-2022-26940 [MEDIUM] CWE-668 GHSA-r3g9-4c8x-fwv7: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-10
Published