Impact
The vulnerability is a use‑after‑free flaw in Windows Remote Desktop Services that allows a malicious actor who has authorized network access to execute arbitrary code on the target system. By triggering the freed memory, an attacker can inject and run malicious payloads without further interaction.
Affected Systems
Affected releases include Microsoft Windows 11 23H2, 24H2, 25H2, and 26H1 as well as Microsoft Windows Server 2025 (both full and Server Core installations).
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not published, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker with authorized access—likely via a compromised or authenticated Remote Desktop session—giving the attacker a foothold to trigger the use‑after‑free and achieve remote code execution.
OpenCVE Enrichment