Impact
A use-after‑free flaw in the Remote Desktop Client allows an unauthorized attacker to execute code over a network. The vulnerability can lead to remote code execution on the affected Windows Server systems. This weakness is categorized as CWE-416 and CWE-787, involving memory corruption that can be exploited to run arbitrary code.
Affected Systems
Microsoft Windows Server 2016, Microsoft Windows Server 2016 (Server Core installation), Microsoft Windows Server 2019, Microsoft Windows Server 2019 (Server Core installation), Microsoft Windows Server 2022, Microsoft Windows Server 2025, and Microsoft Windows Server 2025 (Server Core installation) are affected. Specific affected versions are not listed in the CVE payload, so administrators should review Microsoft documentation for details.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is below 1%, indicating a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is does not require valid credentials; any remote host that can initiate an RDP connection to the affected server could trigger the flaw.
OpenCVE Enrichment