Impact
A heap‑based buffer overflow exists in the Windows Remote Access Connection Manager component. An attacker who already has local access to the system can exploit the vulnerability to gain higher privileges than originally intended. The weakness, identified as CWE‑122, allows the attacker to overwrite critical data structures in memory, potentially compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The flaw affects multiple Windows releases, including Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1, 23H2 (duplicated), and 26H1; Windows Server 2019 (standard and Server Core), Windows Server 2022, and Windows Server 2025 (standard and Server Core). These versions are listed in the CNA vendor/product list and corresponding CPE entries.
Risk and Exploitability
The CVSS base score is 7.8. The EPSS score is 0.01642 (approximately 1.64%), and the vulnerability is not listed in the CISA KEV catalog, which indicates that exploitation probability is low but nonzero. The likely attack vector is local, as the exploit requires an attacker who is already authorized on the target machine; no remote vector is documented. The risk remains considerable because a successful exploit would grant elevated privileges, enabling further attacks such as persistence or lateral movement.
OpenCVE Enrichment