Impact
Use‑after‑free in the Remote Desktop Client allows an unauthorized attacker to execute code over a network. This memory‑corruption flaw is classified as CWE‑416 and CWE‑787. Based on the description, it is inferred that when successfully exploited, the attacker gains full control of the Windows Server.
Affected Systems
Microsoft Windows Server 2016, Windows Server 2016 (Server Core), Windows Server 2019, Windows Server 2019 (Server Core), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core) are affected. No specific sub‑versions are listed, so administrators should refer to Microsoft’s documentation for update details.
Risk and Exploitability
The CVSS score of 7.5 marks the flaw as high severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not in the CISA KEV list. Based on the description, it is inferred that attackers do not need valid credentials; any host that can initiate an RDP session to the server can exploit the flaw.
OpenCVE Enrichment