Impact
Use‑after‑free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. The description does not clarify the privilege level of the executed code, so the safest assumption is that the execution occurs with the same rights as the user running the client, potentially exposing user data and enabling further attacks.
Affected Systems
Affected product versions are Microsoft Windows 10 1809, 21H2, and 22H2; Windows 11 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact, while the EPSS score of less than 1 % shows a very low yet non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector involves an unauthenticated or minimally authenticated Remote Desktop connection from an external network; the adversary must be able to invoke the use‑after‑free during a client‑side session to achieve code execution.
OpenCVE Enrichment