Impact
This flaw is a heap-based buffer overflow (CWE-122) in the Remote Desktop Client that can be triggered by an unauthenticated attacker over the network, allowing arbitrary code execution with the privileges of the client process. It can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 10 21H2 and 22H2, Windows 11 23H2, 24H2, 25H2, 26H1, and Microsoft Windows Server 2022 and 2025 are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.5 indicates a relatively high severity. No EPSS score is reported, so the current estimate of exploitation likelihood is unknown, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves sending crafted data to the Remote Desktop Client over a network connection, without requiring authentication. Such exposure through open or enterprise networks poses a significant threat.
OpenCVE Enrichment