CVE-2022-26940HighCVSS 6.5
Remote Desktop Protocol Client Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of initialized or uninitialized memory in the process heap.
🎯 Affected products5
- Remote Desktop client for Windows Desktop
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.2.3130 KB5013944 (Security Update) — fixed build 10.0.20348.707 KB5013943 (Security Update) — fixed build 10.0.22000.675
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26940
- patchhttps://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/windowsdesktop-whatsnew#updates-for-version-123130
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013944
- referencehttps://support.microsoft.com/help/5013944
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013943
- referencehttps://support.microsoft.com/help/5013943