Impact
The vulnerability is an integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager that allows an authorized attacker to execute code over a network. This flaw is classified as CWE‑191 and permits arbitrary code execution with the privileges of the host process, potentially compromising confidentiality, integrity and availability of the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 (including Server Core), 2012 R2 (Server Core), 2016, 2019, 2022, 2025 (including Server Core). It affects all architectures represented in the CPE list, including x86, x64, ARM64.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity. EPSS is not available so exploitation probability is unknown, and the vulnerability is not listed in KEV. The attack requires an authorized attacker with network access to the Remote Access Connection Manager service; an attacker is likely to exploit the integer underflow by sending a crafted packet that causes a wraparound, leading to remote code execution.
OpenCVE Enrichment