Impact
The vulnerability is a heap‑based buffer overflow in Windows Remote Desktop Services. An attacker with valid RDP credentials can send crafted data that overflows a heap buffer during processing of the Remote Desktop Session Host's internal structures. The overflow allows the attacker to execute arbitrary code within the context of the Remote Desktop Services process, leading to full compromise of the affected system. This weakness is identified as CWE‑122, indicating an uncontrolled buffer overflow that can lead to arbitrary code execution.
Affected Systems
The flaw affects multiple Microsoft Windows releases. Primary targets include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations where applicable. All listed editions are listed in the CVE’s affected vendor/product list.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, while no EPSS score is publicly available. The vulnerability’s risk is compounded by the fact that authenticated users can trigger the overflow, meaning that any account that can log in via Remote Desktop Services presents a potential attack surface. Because the flaw is heap‑based, exploitation requires sending a specifically crafted packet over the RDP protocol, and the impact is full code execution on the target machine. The asset is not listed in the CISA KEV catalog, but the high impact and network‑based nature suggest prioritizing patching.
OpenCVE Enrichment