Impact
A buffer over‑read flaw in the Windows Remote Desktop Client permits an attacker to read beyond the bounds of a memory buffer and transmit that data over the network. Based on the description, it is inferred that the vulnerability is triggered by a malformed RDP packet sent by an unauthenticated adversary. The flaw is a classic unchecked copy error associated with CWE‑126 and only exposes data residing in the client’s memory; it does not provide code execution, privilege escalation, or a denial‑of‑service impact.
Affected Systems
The vulnerability affects multiple Windows releases: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests a very low probability of current exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires network access to a device running the Remote Desktop Client; a crafted RDP packet can trigger the buffer over‑read contents without user interaction.
OpenCVE Enrichment