Impact
The vulnerability is a heap‑based buffer overflow in the Windows Remote Desktop Client. An adversary who can send crafted network data to a client can trigger an uncontrolled write (CWE‑122). This allows the attacker to execute code in the context of the logged‑in user and consequently elevate privileges on the affected system. The flaw is exploitable over the network and could compromise any machine that runs the Remote Desktop Client.
Affected Systems
Microsoft Windows client and server editions are affected. The vulnerable product list includes Windows 10 versions 1607 through 22H2, Windows 11 versions 24H2 through 26H1, and Windows Server editions 2012 (standard and core), 2012 R2 (standard and core), 2016, 2019 (standard and core), 2022, and 2025 (standard and core).
Risk and Exploitability
The CVSS score of 7.5 denotes high severity, and the EPSS score of 1 % indicates a low but non‑zero likelihood of exploitation. The flaw requires network access to the Remote Desktop Client, meaning that systems exposed to RDP traffic over the internet or LAN are at greatest risk. The vulnerability is not yet listed in the CISA KEV catalog. Until a vendor patch is applied, an attacker could potentially exploit the heap overflow to achieve privilege escalation with the privileges of the authenticated user.
OpenCVE Enrichment