Microsoft Windows Server 2019
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*
A buffer over-read vulnerability has been identified in the Remote Desktop Protocol (RDP) implementation of Microsoft Windows. This vulnerability allows an unauthorized attacker to disclose information over the network by exploiting the buffer over-read condition, which can potentially lead to unauthorized access to sensitive data.
Successful exploitation of this vulnerability could allow an attacker to read portions of heap memory, potentially leading to unauthorized information disclosure.
Users can apply the security update KB5099538 for Windows Server 2019, Windows 10 Version 1809 (both 32-bit and x64-based systems), and several other Windows 11 versions. For Windows Server 2022, the security update KB5099540 is available. Windows Server 2012 R2 users can apply the monthly rollup KB5099444. Instructions for downloading these security updates are available through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.