Impact
A heap-based buffer overflow in the Remote Desktop Client allows an attacker to run code on the target machine without authentication. The vulnerability, identified as CWE‑122, can be triggered over network traffic destined for the Remote Desktop protocol, enabling a threat actor to gain arbitrary code execution capabilities. Successful exploitation results in complete compromise of the affected system, giving attackers any privileges the victim process holds.
Affected Systems
Affected are multiple Windows operating systems, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server versions 2016, 2019, 2022, 2025, in both standard and server‑core installations.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. EPSS data is unavailable, and the issue is not listed in CISA KEV, so the exploitation probability is unknown. The attack vector is inferred to be remote network-based traffic to the Remote Desktop service, requiring no prior authentication. Given the broad distribution across recent Windows releases, the risk to systems accessed via RDP is significant.
OpenCVE Enrichment