Impact
A heap‑based buffer overflow (CWE‑122) was discovered in the Remote Desktop Client component. The flaw allows an attacker to execute arbitrary code without needing user interaction. The overflow occurs when processing certain network inputs and can be triggered remotely, giving an attacker the ability to compromise the entire machine.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; the Windows App Client for Windows Desktop; and a range of Windows Server releases from 2012 through 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a remote network connection using the Remote Desktop Client, allowing an unauthorized attacker to exploit the flaw over RDP and execute code, potentially compromising confidentiality, integrity, and availability of the affected systems.
OpenCVE Enrichment