Impact
A heap-based buffer overflow was identified in Windows RNDIS, a remote networking protocol that facilitates USB data transfer. The flaw, classified as CWE‑122, allows an unauthorized network-based attacker to execute arbitrary code during standard operation without requiring local privileges. Through this vulnerability, an attacker could hijack processes, exfiltrate data, or crash the system, thereby compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Microsoft Windows 10 releases 1607 through 22H2, Windows 11 releases 23H2 through 26H1, and Windows Server editions from 2012 to 2025. Both 32‑bit and 64‑bit builds, as well as ARM64 configurations that include the RNDIS stack, are susceptible whenever the default RNDIS drivers are present.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity, although an EPSS score is not publicly available and it is not listed in the CISA KEV catalog. Authentication is not required and the attack surface is exposed over the network, so the risk remains high; exploitation typically involves sending a crafted USB packet to the vulnerable interface.
OpenCVE Enrichment