Impact
The flaw is a use‑after‑free condition in the Remote Desktop Client that lets an attacker trigger arbitrary code execution across the network. It exploits a memory reuse bug identified as CWE‑416 (and also leads to buffer overflows – CWE‑787), allowing the execution of attacker‑supplied code without requiring credentials.
Affected Systems
All Microsoft Windows 10 releases from 1607 through 22H2, Microsoft Windows 11 releases from 23H2 through 26H1, and Windows Server family members from 2012 (including Server Core) through 2025, are affected. The vulnerability resides in the client side of the Remote Desktop Protocol stack and is reachable whenever the Remote Desktop Service is exposed to a network connection.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of <1% suggests a very low likelihood of exploitation at the present moment. The flaw is not listed in the CISA KEV catalog and is believed to be exploitable purely via an RDP session, with no authentication required, making any machine reachable over RDP a potential target.
OpenCVE Enrichment