CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007255 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25769Patch KB5007233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23517Patch KB5007245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007247 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19119Patch KB5007207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.318Patch KB5007215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.2600 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is CVE-2021-38665?
CVE-2021-38665 is a vulnerability that allows an attacker to disclose sensitive information through the Remote Desktop Protocol (RDP) client.
What software is affected by CVE-2021-38665?
Microsoft Remote Desktop client for Windows Desktop, Microsoft Windows 10 (all versions), Microsoft Windows 11 (arm64 and x64), Microsoft Windows 7 (with Service Pack 1), Microsoft Windows 8.1, Microsoft Windows RT 8.1, Microsoft Windows Server 2008 (with Service Pack 1), Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows Server 2019, and Microsoft Windows Server 2022 are affected by CVE-2021-38665.
What is the severity of CVE-2021-38665?
CVE-2021-38665 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2021-38665?
To fix CVE-2021-38665, it is recommended to apply the security updates provided by Microsoft.
Where can I find more information about CVE-2021-38665?
You can find more information about CVE-2021-38665 on the Microsoft Security Portal.