Impact
The updated description clarifies that a use‑after‑free in the Remote Desktop Client component allows an unauthenticated network attacker to execute code on the compromised machine. This memory‑management flaw, identified as CWE-416 (Use After Free) and CWE-787 (Out‑of‑Bounds Write), enables arbitrary code execution, giving the attacker full control over the target system.
Affected Systems
Affected systems include Microsoft Remote Desktop Client for Windows Desktop, Windows App Client for Windows Desktop, and the Remote Desktop Client component present in Windows Server installations. All Windows 10 editions 1607, 1809, 21H2, and 22H2, all Windows 11 editions 23H2, 24H2, 25H2, and 26H1 (including ARM64 variants) are impacted, as are all Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates high impact, and the EPSS score of <1% shows a very low likelihood of exploitation in today’s threat landscape. An unauthenticated attacker who can reach the client over the network can trigger the overflow and achieve arbitrary code execution on the host. Authentication is not required, and only network access to the RDP client is needed for exploitation.
OpenCVE Enrichment