Impact
Deserialization of untrusted data in the Microsoft High Performance Computing (HPC) Pack allows an attacker who can send crafted data over the network to execute arbitrary code on a machine running the Windows App Client. This flaw falls under the input validation and deserialization weakness identified as CWE-502 and can lead to full compromise of the affected system, including data theft, tampering, or use as a pivot point for further attacks.
Affected Systems
Microsoft Windows App Client for Windows Desktop is affected. Specific product versions were not disclosed in the advisory, so all current and legacy installations of the HPC Pack client should be considered vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. Its EPSS score of 2% indicates a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network where the HPC Pack client is reachable; an attacker can send malicious serialized data to trigger the flaw.
OpenCVE Enrichment