Impact
Concurrent execution using shared resource with improper synchronization ('race condition') in the Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Affected Systems
Microsoft Remote Desktop client for Windows Desktop, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Windows Server 2022 and 2025, including Server Core installations are affected. The vulnerability exists in the client component across these Windows releases without a specified patch version in the description.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating high severity. The EPSS score is < 1%, indicating a low but non‑zero exploitation probability; the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploits yet. Nonetheless, achieving remote code execution, the risk remains significant. The likely attack vector involves sending malicious RDP packets to an exposed Remote Desktop service, so an attacker with network access can exploit the flaw if the client is in use.
OpenCVE Enrichment