Impact
A heap-based buffer overflow exists in the RPC Runtime library that allows an attacker who can send specially crafted network requests to execute arbitrary code. Based on the description, it is inferred that this execution would run under the RPC service privileges. This flaw, identified as CWE‑122, can result in a full compromise of the affected host, enabling the attacker to install malware, exfiltrate data, or expand lateral movement within the network.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and Windows Server 2012 through 2025, including core installations, are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity flaw. EPSS is reported as <1%, indicating a very low exploit probability at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires network connectivity to RPC services and the delivery of crafted input, which makes it feasible for an unauthenticated attacker on an untrusted network. Because the flaw is remote and privileged, it is a significant risk, yet the current exploitation probability is low, so organizations should prioritize patching and monitor for any attempted exploitation.
OpenCVE Enrichment