Impact
A use–after–free flaw in the Windows Remote Desktop Licensing Service allows an attacker who is already authenticated on the network to gain elevated privileges. The attacker can exploit the vulnerability to execute code with higher privileges than intended, potentially leading to full system compromise and unauthorized access to sensitive data.
Affected Systems
The flaw affects Windows 10 versions 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations of each edition.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity vulnerability. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting currently limited exploitation data. Nonetheless, the flaw requires network-based access to the Remote Desktop Licensing Service and is exploitable by a legitimate user on the network, positioning it as a notable risk for environments where the service is exposed to untrusted or compromised hosts.
OpenCVE Enrichment