Impact
The vulnerability is a heap‑based buffer overflow located in Microsoft Remote Desktop Client that permits an attacker who can send specially crafted data over a network to execute arbitrary code on the target system. This flaw is identified as CWE‑416, indicating a lack of bounds checking during heap operations. The vulnerability can be triggered without authentication and solely requires network communication with the client.
Affected Systems
Affected systems include the Microsoft Remote Desktop Client for Windows Desktop as well as all listed Windows 10 editions (1607, 1809, 21H2, 22H2) and Windows 11 editions (23H2, 24H2, 25H2, 26H1, including ARM64 variants). Additionally, all Windows Server editions from 2012 through 2025, including Server Core installations, are impacted because they incorporate the Remote Desktop Client component.
Risk and Exploitability
The CVSS score of 7.5 indicates high impact, while the lack of an EPSS score leaves the exact likelihood of exploitation uncertain. The vulnerability is not currently listed in CISA’s KEV catalog. An unauthenticated attacker who can reach the Remote Desktop Client over a network can trigger the overflow, leading to arbitrary code execution on the host. Edition update availability is not indicated here, so assuming a patch is available but containment controls are advisable until it is applied.
OpenCVE Enrichment