Impact
The vulnerability is a heap‑based buffer overflow in the Remote Desktop Client component. An attacker who can send crafted data to an affected system can gain arbitrary code execution. The flaw allows unauthorized remote code execution over the network without user interaction.
Affected Systems
The flaw affects multiple Microsoft Windows products. Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and the Windows Server family including 2012, 2012 R2, 2016, 2019, 2022, and 2025. Both standard and core installations are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high potential for impact. With no EPSS score available, the current known exploitation probability is unclear, and the vulnerability is not catalogued in the CISA KEV list. Attackers could potentially exploit the flaw over a network connection, targeting the Remote Desktop Client. The lack of a KEV listing does not mean the flaw is safe, and remediation remains prudent.
OpenCVE Enrichment