Impact
A heap‑based buffer overflow exists in the Windows Remote Access Connection Manager component. When triggered, the flaw allows a user who already has local access to the system to execute arbitrary code with local privileges. The vulnerability is a classic out‑of‑bounds write, corresponding to CWE‑122.
Affected Systems
The flaw affects numerous Microsoft Windows releases, including Windows 10 build 1607, 1809, 21H2 and 22H2; Windows 11 builds 23H2, 24H2, 25H2, 26H1; and Windows Server 2012 through Server 2025 whether in full or core installations.
Risk and Exploitability
The base CVSS score is 7.8, indicating a high severity. EPSS data is not available, leaving the precise exploitation probability unclear; however, the vulnerability is known to be local and requires the attacker to have logged on to the system. It is not listed in the CISA KEV catalog and no public exploits have been released, but the local permission requirement means that any user with sufficient rights could abuse the flaw if no mitigations are applied.
OpenCVE Enrichment