Impact
The vulnerability arises from a missing authentication check in a critical function of Windows Remote Desktop Services, corresponding to CWE‑306. An attacker who has already authenticated to a Remote Desktop session can exploit this flaw to gain elevated privileges on the host. By bypassing authentication, the attacker can execute code with SYSTEM rights, allowing full control of the affected machine, including data theft, malware installation, and complete system takeover.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, 22H2; Microsoft Windows 11 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012 (Standard and Core), 2012 R2 (Standard and Core), 2016, 2019, 2022, and 2025 (Standard and Core).
Risk and Exploitability
The flaw has a CVSS score of 7.8, classifying it as high severity, but its EPSS score is not available. It is not listed in the CISA KEV catalog. The likely attack vector is a local privilege escalation inside an already authenticated Remote Desktop session, meaning the attacker must first obtain legitimate RDP credentials or achieve a compromised account. Once exploited, the attacker can gain full system control. Given the high severity and potential impact, timely remediation is strongly recommended.
OpenCVE Enrichment