Impact
The vulnerability is a heap-based buffer overflow that allows an attacker without local privileges to overflow a buffer in the Remote Desktop Client and execute arbitrary code. The resulting compromise can give the attacker full control of the target machine, impacting confidentiality, integrity, and availability. The vulnerability is classified as CWE-122.
Affected Systems
Affects Microsoft Remote Desktop client for Windows desktop. No specific product versions are listed in the CNA data, so any installation of the Windows Remote Desktop client is potentially vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high criticality. EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is likely over the network, requiring the client to connect to a Remote Desktop server; an attacker may trigger the overflow by sending specially crafted traffic between client and server. Until a patch is installed, the system remains at risk of exploitation.
OpenCVE Enrichment