Impact
A use-after-free flaw in Windows Remote Desktop Services lets an authorized attacker execute arbitrary code over the network, enabling full compromise of confidentiality, integrity, and availability on the affected machine. The bug correlates with CWE-416, a memory-management defect that can turn a benign input into a malicious payload. Attackers leveraging this flaw can run custom binaries, install ransomware, or pivot to other network resources.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025, including all core installations. The vulnerability applies to both x86 and x64 platforms across these releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk level, and although the EPSS score is not available, the lack of KEV inclusion does not imply low risk—the vulnerability remains actively exploitable by an attacker able to initiate an authenticated Remote Desktop session. The attack path requires establishing a network connection to the Remote Desktop Services endpoint, after which a privileged attacker can trigger the use‑after‑free to execute code. Given the remote nature of the exploit, protection of RDP exposure is critical.
OpenCVE Enrichment