Impact
A use‑after‑free defect in the Windows Remote Desktop Services kernel component allows an attacker who can connect to the RDP service to trigger memory corruption that results in code execution with the privileges of the target local account. The vulnerability (CWE‑362) coupled with unauthorized use of freed memory (CWE‑416). If successfully exploited, the attacker can gain higher privileges on the host, potentially allowing full system compromise. The CVE description states that the flaw is exploitable by an authorized attacker on the network, indicating a remote threat model.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2016 Core, 2019, 2019 Core, 2022 and 2025 (including all Server Core installations). Architecture variants include x86, x64 and arm64 as disclosed.
Risk and Exploitability
The CVSS score of 8.8 categorises the flaw as high severity, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely but it remains a critical risk for exposed RDP endpoints. Because the vulnerability is not listed in CISA’s KEV catalogue, general warning signals are limited, yet all affected systems that allow Remote Desktop Connections remain vulnerable. The likely attack path to reach the RDP service over the network; from there an ill‑crafted packet targeting the use‑after‑free can be sent to elevate privileges on that host.
OpenCVE Enrichment