Impact
The vulnerability is a heap‑based buffer overflow in the Windows Remote Access API. An attacker who already has authorized access to a Windows system can craft a malicious request that overflows a heap buffer within the API. The overflow enables the attacker to execute arbitrary code with elevated privileges, effectively turning a lower‑privileged user account into an administrator or system level account. This is classified as a privilege‑escalation flaw (CWE‑122).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations). The flaw is present in all of these builds.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact. EPSS is below 1%, implying the likelihood of exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to be authenticated or otherwise authorized to use the Remote Access API, which is typically intended for trusted administrative operations. Once the buffer overflow is triggered, the attacker can gain full local privileges. System administrators should treat this as a high‑risk issue and apply patches promptly.
OpenCVE Enrichment