Impact
This vulnerability is a remote code execution flaw that arises from the use of an uninitialized resource within the Remote Desktop Client. An attacker that has authorization to access the remote desktop session can trigger code execution across the network. The flaw falls under CWE‑908 and could allow an attacker to run arbitrary code with the privileges of the client process, potentially compromising the confidentiality, integrity, or availability of the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2016, 2019, 2022, and 2025 in both standard and Server Core installations are specifically affected. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, but the lack of KEV listing suggests no confirmed widespread exploitation yet. The likely attack vector is a network-based attack that requires the attacker to be authorized to open a remote desktop session. The attacker can trigger the flaw through normal remote desktop usage, leading to authorized code execution on the client side.
OpenCVE Enrichment