Impact
The vulnerability is a use‑after‑free in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. This memory‑management flaw, identified as CWE‑416 and CWE‑787, enables the attacker to hijack execution flow on the host system, potentially gaining full control.
Affected Systems
Microsoft Remote Desktop Client for Windows Desktop, Windows App Client for Windows Desktop, and the Remote Desktop Client component in Windows Server builds are affected. All Windows 10 editions 1607, 1809, 21H2, and 22H2; Windows 11 editions 23H2, 24H2, 25H2, 26H1 (including ARM64 variants); and Windows Server builds 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations, are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high impact, while the EPSS score of < 1 % shows a very low current exploitation rate. Based on the description, it is inferred that the attack vector is a remote network connection to the RDP client; no authentication is required and only network access to the client is necessary to trigger the overflow and achieve arbitrary code execution. The vulnerability is not listed in the CISA KEV catalog, suggesting a lower prevalence in commercial exploitation.
OpenCVE Enrichment