Impact
A stack-based buffer overflow in the Remote Desktop Client enables an attacker to cause remote code execution. The overflow occurs when processing certain network requests, allowing the attacker to inject and execute arbitrary code on the host system. This can compromise the confidentiality, integrity, and availability of the affected machine.
Affected Systems
Affected products include Microsoft Windows 10 Version 1607 and Windows Server 2012, 2012 R2, and 2016, both full and Server Core installations. The exact CVE references indicate that any installation of these operating systems containing the default Remote Desktop Client is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity vulnerability. EPSS is not available, indicating limited availability of exploitation data, and the CVE is not listed in the CISA KEV catalog. The likely attack vector is a remote network connection to the Remote Desktop Service (port 3389); an attacker who can reach this service may trigger the buffer overflow and obtain arbitrary code execution.
OpenCVE Enrichment