Impact
A use‑after‑free flaw in Windows Remote Desktop Services lets an attacker who already has local access elevate privileges on the host. The vulnerability occurs when the service reuses freed memory, allowing the attacker to subvert execution flow, potentially run arbitrary code, alter system state, or bypass confinement limits. This defect is identified as CWE‑416 and constitutes a local privilege escalation risk.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2 to 26H1), and Microsoft Windows Server (2012 through 2025, including Server Core installations).
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity. No EPSS value is available, suggesting limited confirmed exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local or authenticated Remote Desktop access; the attacker must be able to run code within the vulnerable RDS process to trigger the use‑after‑free. If triggered, the attacker can gain elevated privileges on the affected system.
OpenCVE Enrichment