Microsoft Windows Remote Procedure Call Information Disclosure Vulnerability

Vulnerability

A vulnerability in Windows Remote Procedure Call (RPC) allows unauthorized attackers to locally disclose sensitive information. This issue affects several versions of Windows, including various Windows Server editions and Windows 10 and 11 releases. The vulnerability could lead to the unauthorized disclosure of one byte of kernel memory.

Impact

Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information, specifically one byte of kernel memory, to an attacker.

Remediation

Users can apply the security update for this vulnerability, which is included in the January 2026 Monthly Rollup, available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5073724 for Windows 10, KB5073722 for Windows Server 2016, KB5073723 for Windows Server 2019, and KB5073457 for Windows Server 2022.

Added: Jan 13, 2026, 8:16 PM
Updated: Jan 13, 2026, 8:16 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.