CVE-2026-57098: Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
Other sources
Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.7279.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is network-reachable and requires no attacker privileges or user interaction, according to the supplied vector. Exploitation is described as allowing an unauthorized attacker to disclose information over a network.
What is the expected impact if exploitation succeeds?
The stated impact is information disclosure with high confidentiality impact. No integrity or availability impact is indicated in the supplied severity vector.
Which product is identified as affected?
The affected software is identified as the Microsoft Remote Desktop client for Windows Desktop. The provided data does not specify affected versions, fixed versions, or configuration conditions.