Impact
The vulnerability is a use‑after‑free flaw in Windows Remote Desktop Services that permits an attacker who has already authenticated to the target system to execute arbitrary code on the machine. The flaw lies in the handling of RDP packets that free memory before any further checks, allowing the attacker to manipulate the freed pointer. The primary impact is remote code execution, giving the attacker full control over the operating system, potentially leading to data theft, privilege escalation, and system compromise.
Affected Systems
Affected systems are Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025, including the Server Core installation. The platforms impacted include x64 and arm64 architectures, as shown by the common platform enumeration strings. All these releases provide Remote Desktop Services and have not yet received the official Microsoft patch listed in the update guide.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as high severity, and the lack of an EPSS value means there is no publicly available data on exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, but the typical remote attack vector exploits the RDP interface over the network, requiring the attacker to be authenticated or have valid credentials to the target machine. If exploited, the attacker could execute arbitrary code, compromise confidentiality, integrity, and availability of the system, and potentially use the machine as a pivot point for further attacks.
OpenCVE Enrichment