CyberICT

CVE-2026-56171

Microsoft · Published July 16, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability. Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

Affected Products

  • Windows Admin Center
  • Remote Desktop Web Client

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C