Impact
The vulnerability is a missing authentication check for a critical function in Windows Remote Desktop Services that enables an authorized local attacker to elevate privileges on the affected system. This flaw can give the attacker full administrator rights, allowing unrestricted read, write, and execution capabilities. The impact is limited to the local system as the flaw requires local access and authentication to the remote desktop session.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including all Server Core installations. The affected devices are listed by their common platform enumeration strings as provided by the CVE entry.
Risk and Exploitability
The base CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. The likely attack vector is a local, authenticated attacker leveraging Remote Desktop Services to trigger the privilege escalation. The risk is heightened for systems exposed to Remote Desktop and lacking a timely patch.
OpenCVE Enrichment