Impact
A heap‑based buffer overflow in Microsoft’s Remote Desktop Client permits an attacker to execute arbitrary code on any Windows desktop running the vulnerable client. The flaw is triggered when the client processes data received over a network connection. Successful exploitation would give the attacker full control of the host environment, compromising all user processes and data.
Affected Systems
The problem exists in the Remote Desktop Client for Windows Desktop distributed by Microsoft. No specific version was disclosed in the advisory, so any installation of this client that has not been updated to the latest release may be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % shows that the likelihood of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog, and no large‑scale attacks have been reported. An attacker only needs to deliver crafted data over the network; no user credential is required. Successful delivery leads to remote code execution on the target host.
OpenCVE Enrichment