CVE-2021-38631: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007255 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21282Patch KB5007246 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23517Patch KB5007245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25769Patch KB5007233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007247 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.318Patch KB5007215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19119Patch KB5007207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38631?
CVE-2021-38631 has a severity rating of Medium due to its potential for information disclosure.
How do I fix CVE-2021-38631?
To fix CVE-2021-38631, apply the latest security updates from Microsoft for affected Windows versions.
Which operating systems are affected by CVE-2021-38631?
CVE-2021-38631 affects multiple versions of Windows including Windows 7, 8.1, 10, 11, and several Windows Server editions.
What type of vulnerability is CVE-2021-38631?
CVE-2021-38631 is categorized as an Information Disclosure vulnerability in the Windows Remote Desktop Protocol.
Can CVE-2021-38631 be exploited remotely?
CVE-2021-38631 can potentially be exploited by an attacker with network access to the RDP service.