Impact
A heap‑based buffer overflow in the Remote Desktop Client component enables an unauthenticated attacker to execute arbitrary code on a target computer. Based on the description, it is inferred that the vulnerability is triggered by malformed RDP traffic, leading to arbitrary code execution and the potential compromise of confidentiality, integrity, or availability of the affected system. This flaw represents classic memory corruption weaknesses (CWE‑122 and CWE‑20).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity vulnerability. The EPSS score is less than 1%, indicating a low probability of exploitation at the current time, though the flaw is in a widely used remote desktop protocol that is often exposed to the Internet. The vulnerability is not listed in CISA’s KEV catalog. Attackers could exploit this remotely over standard RDP ports, requiring no local privileges or authentication; thus, the attack vector is inferred to be a remote network‑based exploitation.
OpenCVE Enrichment