Impact
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. The description does not specify the privilege level of the executed code, but it is commonly inferred that the code runs with the privileges of the user running the client at the time of exploitation.
Affected Systems
Affected product versions are Microsoft Windows 10 1809, 21H2, and 22H2; Windows 11 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact, while the EPSS score of less than 1 % shows a very low yet non‑zero probability of exploitation. It is not listed in the The likely attack vector involves an unauthenticated or minimally authenticated Remote Desktop connection from an external network; the adversary must be able to invoke the use‑after‑free during a client‑side session to achieve code execution.
OpenCVE Enrichment