Impact
A heap‑based buffer overflow exists in the Windows Remote Access Connection Manager. The flaw allows an attacker who already has local access to overwrite memory and execute arbitrary code with elevated privileges, potentially gaining full system or administrative rights. The vulnerability is a classic unchecked buffer manipulation (CWE‑122) and could be used to install malware, modify system settings, or exfiltrate data.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including server core installations. All affected systems contain the Remote Access Connection Manager component in which the buffer overflow occurs.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity, and the vulnerability requires only local authorized access, meaning any user with local access is a potential attacker. EPSS data is not available, so the precise exploitation probability is unknown, but the lack of KEV listing indicates no publicly known attacks yet. If exploited, the attacker can elevate to administrator level, compromising confidentiality, integrity, and availability of the affected machine.
OpenCVE Enrichment