CVE-2022-26940

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published May 10, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-26940 is a newly discovered vulnerability affecting Remote Desktop Protocol (RDP) clients. This issue permits an unauthenticated attacker to obtain sensitive information by manipulating RDP packets. The vulnerability exists due to an information disclosure weakness in the way RDP clients handle certain requests. Successful exploitation could lead to the exposure of system and user details, increasing the risk of further attacks. It is recommended that organizations and individuals apply the necessary patches or updates as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Windows Server 2022
  • Microsoft Windows 11
  • Microsoft Remote Desktop

Affected Vendors

  • Microsoft