Impact
The likely attack vector is an unauthenticated Remote Desktop Protocol (RDP) session over the network. The flaw is a use‑after‑free vulnerability in the Remote Desktop Client that permits an attacker without credentials to run arbitrary code over the network. Because it can be triggered merely by establishing an RDP session, any host with Remote Desktop Service exposed to the Internet is a potential target and can be fully compromised. The issue exploits memory reuse leading to a buffer overflow, as indicated by CWE‑416 and CWE‑787.
Affected Systems
All Microsoft Windows 10 releases from 1607 through 22H2, Microsoft Windows 11 releases from 23H2 through 26H1, and Windows Server family members from 2012 to 2025 (including Server Core), are affected. The flaw resides in the client side of the Remote Desktop Protocol stack and is reachable whenever the Remote Desktop Service is exposed to a network connection.
Risk and Exploitability
Based on the description, it is inferred that the flaw is exploitable purely via an RDP session. The CVSS score of 8.8 indicates high severity. The EPSS score of <1% suggests a very low likelihood of exploitation at the present moment. The flaw is not listed in the CISA KEV catalog and is believed to be exploitable purely via an RDP session, with no authentication required, making any machine reachable over RDP a potential target.
OpenCVE Enrichment