Impact
Heap-based buffer overflow in Windows Remote Desktop Service allows an attacker who can send specially crafted packets over a network to execute arbitrary code with the privileges of the service. This flaw is a classic remote code execution (CWE‑122) that can compromise confidentiality, integrity and availability of the affected system.
Affected Systems
Vulnerable products include Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2, Windows 11 releases 23H2, 24H2, 25H2, and 26H1, and Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is assessed as high severity, and although EPSS data is not available, the lack of a KEV listing suggests the vulnerability has not yet been widely abused in the field, but it remains exploitable over a network from an unauthenticated attacker. The likely attack vector is remote via the Remote Desktop Protocol; an attacker can send malicious RDP packets to trigger the overflow without prior authentication.
OpenCVE Enrichment