Impact
Heap-based buffer overflow in the Windows Remote Access Connection Manager can be triggered by a local, authorized user to elevate privileges. The flaw occurs during allocation of heap memory, allowing an attacker to overwrite critical data and gain higher access rights on the system. This reliance on an existing local session means the impact is a local privilege escalation rather than a remote compromise.
Affected Systems
Microsoft products including Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022, 2025 and their respective server core installations are affected by the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 reflects the severity of the local privilege escalation. With EPSS not available and the vulnerability not listed in the CISA KEV catalog, no current public exploits are known. The likely attack vector requires an authorized local user; an attacker would need to run code with their own credentials to trigger the overflow. Despite the absence of remote access, the high potential for privilege escalation makes the vulnerability significant for any machine with vulnerable software exposed to internal users.
OpenCVE Enrichment