Impact
The vulnerability is an out‑of‑bounds read in the Windows Remote Desktop Licensing Service. The flaw enables an authorized attacker with local access to read memory regions outside the intended buffer, potentially exposing sensitive data on the affected system. The impact is a local information disclosure that can leak confidential information to the attacker, but it does not provide elevated privileges or remote access.
Affected Systems
The affected products are various Windows operating systems, including multiple editions of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and several Windows Server releases (2012, 2012 R2, 2016, 2019, 2022, 2025). Systems running any of these versions are vulnerable if the Remote Desktop Licensing Service is present.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate threat level. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. The flaw can be leveraged by an attacker who already has local or authorized access to the target – for example, a local administrator or a privileged user – and does not require remote code execution or network compromise. The absence of broader exploitability details means that defensive measures focused on local privilege control remain effective.
OpenCVE Enrichment