Impact
The vulnerability is a use‑after‑free in Microsoft Remote Desktop client. An attacker who can send crafted remote desktop traffic to a vulnerable client can cause the program to dereference freed memory and execute attacker‑controlled code. This grants the attacker full code execution rights in the context of the client process, potentially compromising the system’s confidentiality, integrity, and availability.
Affected Systems
The flaw affects Microsoft Remote Desktop client for Windows Desktop, Remote Desktop App Client, and Remote Desktop functionality in multiple Microsoft operating systems. Specifically, Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 releases 23H2, 24H2, 25H2, 22H3, 26H1, and Windows Server editions from 2012 to 2025, including core installations.
Risk and Exploitability
The CVSS base score of 8.8 places the flaw in the high‑severity range. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack vector is network‑based and does not require local privileges, it can be executed by an adversary able to communicate with the Remote Desktop client. Based on these facts, the likelihood of exploitation is inferred to be moderate to high, though precise probability cannot be quantified without EPSS data.
OpenCVE Enrichment