Impact
Out‑of‑bounds read in Windows Remote Desktop Services can be exploited by an authorized attacker to elevate privileges on the local system. The flaw allows a read beyond the intended memory boundary, revealing sensitive information that can be leveraged to gain higher privileges. The primary impact is unauthorized elevation of privileges, potentially compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations). These operating systems include the vulnerable Windows Remote Desktop Services component.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the lack of EPSS data means the current exploitation probability is unknown. The flaw is listed in the Microsoft security advisory but is not present in the CISA KEV catalog, implying no widely known exploits yet. The likely attack vector is remote network traffic, where an attacker who already has some level of access can craft malicious RDP packets to trigger the out-of-bounds read and elevate privileges.
OpenCVE Enrichment