Impact
A heap‑based buffer overflow in the Windows Remote Network Driver Interface Specification (RNDIS) component allows an attacker to read memory contents and thereby disclose sensitive information. The vulnerability results from insufficient bounds checking when the RNDIS data path processes certain inputs, giving the attacker the ability to retrieve data that should remain protected by the operating system's memory protection mechanisms. The weakness corresponds to CWE‑122, a classic heap corruption scenario.
Affected Systems
Microsoft Windows 10 and Windows 11 systems with the following release versions are impacted: 1607, 1809, 21H2, 22H2, 23H2, 24H2, 25H2, and 26H1, along with Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations. These versions span both 32‑bit and 64‑bit architectures as well as ARM variants where applicable.
Risk and Exploitability
The CVSS score of 4.6 places the severity in the low range, and the exploitability metrics are currently unavailable. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The primary attack vector appears to be physical access to the RNDIS interface, such as a wired connection to a device that uses the RNDIS protocol. Because the exploit requires close proximity to the target system, the realistic threat exposure is limited, but the potential for confidential data leakage remains.
OpenCVE Enrichment