CVE-2012-2526: Microsoft Windows XP

High severity, CVSS 9.3. EPSS: 25% chance of exploitation in the next 30 days.

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP3 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to a deleted object, aka "Remote Desktop Protocol Vulnerability."

Affected products

Published 2012-08-15. Last modified 2026-06-16.