Impact
The vulnerability is rooted in a race condition in the Remote Desktop Client where concurrent execution using a shared resource fails to protect against improper synchronization. As a result, an unauthorized attacker can remotely execute arbitrary code on affected systems via network traffic. This flaw is a classic example of a synchronization race condition (CWE‑362) that can compromise confidentiality, integrity, and availability of the affected operating systems.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and a range of Windows Server releases from 2012 through 2025, including Server Core installations of the 2012 and 2012 R2 editions, along with Windows Server 2016, 2019, 2022, and 2025.
Risk and Exploitability
The assessment gives a CVSS score of 7.5, indicating a high severity impact, while the EPSS score is below 1 %, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the affected Remote Desktop Client; an attacker would need to trigger the race condition through crafted network traffic to gain code execution. Given the moderate‑to‑high severity and the rarity of exploitation attempts, organizations should still treat this as a serious risk, especially if Remote Desktop services are widely exposed.
OpenCVE Enrichment