Impact
The vulnerability is an integer overflow or wraparound in the Windows Remote Desktop Client that can be triggered by receiving specially crafted Remote Desktop Protocol packets. When the overflow occurs, the client application crashes, causing the remote session to terminate and denying the user the ability to connect. The impact is limited to availability, with no direct compromise of data confidentiality or integrity.
Affected Systems
Affected platforms include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, including server core installations. The Common Platform Enumeration identifiers confirm coverage across x86, x64, and some ARM64 architectures.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is below 1%, implying a low but nonzero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a network-based attacker who can send malformed RDP frames to a target with Remote Desktop enabled. Because no authentication is required, any exposed RDP session could be disrupted. The risk is moderate, especially for environments that rely heavily on RDP for remote management.
OpenCVE Enrichment