Impact
A heap‑based buffer overflow exists in the Windows Telnet Client, allowing an attacker who can send specially crafted data over the network to execute arbitrary code with the privileges of the user running the client. The flaw is exploitable without authentication and can lead to full system compromise.
Affected Systems
Affected products include Microsoft Windows 10 (Versions 1607, 1809, 21H2, 22H2), Windows 11 (Versions 23H2 through 26H1), and Windows Server 2012 through 2025, including Server Core installations of 2012, 2012 R2, 2016, 2019, 2022, and 2025. All listed system variants are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score is not available. The vulnerability is not yet listed in CISA KEV. The likely attack vector is remote network traffic over the Telnet service (TCP port 23). An unauthenticated attacker can trigger the overflow by sending a malicious payload, thereby gaining code execution on the affected machine without additional privileges.
OpenCVE Enrichment