Impact
A heap‑based buffer overflow exists in the Remote Desktop Client that can be triggered by an attacker who initiates a connection. The flaw allows the execution of arbitrary code on the target system with the privileges of the Remote Desktop Service. The vulnerability is identified by CWE-122 and represents a critical security flaw that could compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely but not impossible. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the most probable attack vector is a remote RDP session initiated by an unauthenticated attacker over the network, implying that exposure to the internet increases risk.
OpenCVE Enrichment