Impact
A use‑after‑free flaw in the Microsoft Remote Desktop Client allows an unauthorized attacker to execute arbitrary code over a network.
Affected Systems
Microsoft Remote Desktop Client for Windows Desktop, Windows App Client for Windows Desktop and all listed Windows 10 releases (1607, 1809, 21H2, 22H2, 23H2, 24H2, 25H2, 26H1) and Windows 11 releases (23H2, 24H2, 25H2, 26H1) are impacted. The same applies to Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025. All 32-bit, 64-bit and ARM64 builds are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is reported below 1 %, suggesting a low probability of exploitation under current conditions. The vulnerability is not listed in CISA KEV. The likely attack vector is a remote network connection in which an attacker gains control of the remote endpoint or dispatches malicious RDP packets. It is inferred that any untrusted RDP session or malformed packet can trigger the flaw, allowing code execution without local privileges and potentially leading to full system compromise.
OpenCVE Enrichment