Impact
The flaw is a missing authentication check for a critical operation in Windows Remote Desktop Services, which allows an authorized attacker to elevate privileges on the affected system. This defect is a classic authentication flaw (CWE-306) and can result in an attacker gaining the same rights of the service process, enabling them to modify system settings, install malware, or exfiltrate data using elevated privileges.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote session via Remote Desktop Services, where an authenticated user exploits the missing authentication to elevate privileges. Because the flaw affects the critical Remote Desktop Services component, a successful exploitation grants system-wide control. Given the high CVSS value and the broad scope of potential damage, organizations should treat this as a high risk.
OpenCVE Enrichment