Impact
A use‑after‑free flaw has been discovered in Windows Remote Desktop Services that allows an attacker to execute arbitrary code over a network. The vulnerability is a classic memory safety error (CWE‑416) where an object is dereferenced after being freed, permitting the injection of malicious code that runs with the privileges of the RDS service. Successful exploitation would compromise confidentiality, integrity, and availability of the affected system, allowing an attacker to gain unrestricted control.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, and the server core installations of these editions. Systems using either x86, x64, arm64, or other architectures listed in the CPE entries are impacted.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating a very high severity. The EPSS score is 1%, suggesting a low but non‑zero probability of exploitation in the wild, but the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is remote and unauthenticated over the RDP port (3389), inferred from Remote Desktop Services' typical usage. An attacker can send a specially crafted packet to Remote Desktop Services to trigger the use‑after‑free and execute code with service‑level privileges. The absence of known mitigations beyond a patch means that affected installations remain highly vulnerable if left unaddressed.
OpenCVE Enrichment