Impact
Use after free in the Remote Desktop Client allows an unauthorized attacker to execute code over a network. The flaw arises when the client releases an object and subsequently performs an out‑of‑bounds access that can overwrite critical data. This memory corruption enables the attacker to run arbitrary code on the client machine without local privileges, potentially leading to full system compromise. The weakness maps to CWE‑416 (Use After Free) and CWE‑787 (Out‑of‑Bounds Write).
Affected Systems
Microsoft Remote Desktop Client for Windows Desktop and Windows App Client for Windows Desktop are affected, along with all enumerated Windows 10 releases—from 1607 through 26H1—including 32‑bit, 64‑bit and ARM64 builds. The same vulnerability applies to Windows 11 releases 23H2, 24H2, 25H2 and 26H1 across all processor architectures. Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 are also impacted for both standard and Core installations in all supported bitnesses.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is classified as high severity. The EPSS score of approximately 1.3 % indicates a low but non‑negligible exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote RDP connection that an attacker initiates or manipulates, such that a malicious or malformed packet triggers the memory corruption. Because the flaw is client‑side, the attacker does not need local access or credentials and can achieve arbitrary code execution at the client’s level, potentially yielding full control of the affected machine.
OpenCVE Enrichment