Impact
This vulnerability is a heap-based buffer overflow in the Remote Desktop Client. An attacker who can reach the client over a network could trigger the overflow and cause arbitrary code execution with the privileges of the logged‑on user, leading to complete compromise of the client system. The weakness corresponds to CWE-122.
Affected Systems
Affected are multiple Windows desktop and server editions. On desktop products, Windows 10 and Windows 11 from the listed versions (1607, 1809, 21H2, 22H2, 23H2, etc.) and ARM64 variants are impacted. On server platforms, all editions from Windows Server 2012 through Windows Server 2025, including core installations, are vulnerable. The specific versions are enumerated in the CNA product list.
Risk and Exploitability
The CVSS score of 8.8 marks this as high severity, while no EPSS data is publicly available, indicating that the probability of exploitation is undefined. The vulnerability is not currently listed in the CISA KEV catalog, so there is no known widespread exploitation. Based on the description, the likely attack vector is a remote connection to the RDP service over the network, and exploitation requires an attacker with network access to reach the vulnerable Remote Desktop Client. No privileged execution is required for the initial overflow, but the attack succeeds once the buffer is corrupted.
OpenCVE Enrichment