Impact
The vulnerability is a race condition caused by concurrent execution using a shared resource with improper synchronization in the Remote Desktop Client, enabling an unauthorized attacker to execute code over a network. The weakness, characterized by concurrent access issues, falls under CWE‑362 and CWE‑416.
Affected Systems
Microsoft Remote Desktop client for Windows Desktop and Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and 2025, including Server Core installations are affected. The flaw exists across these Windows releases, and no specific patch version is indicated in the description.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating high severity, while the EPSS score is < 1%, suggesting a low but non‑zero exploitation probability. It is not listed in CISA’s KEV catalog, implying no confirmed exploits yet. The likely attack vector involves an adversary with network access sending malicious RDP packets to a target session, exploiting the race condition to execute code remotely.
OpenCVE Enrichment