Executive brief
Windows RNDIS (Remote Network Driver Interface Specification) is a network driver component used by Windows systems for network communication. A heap-based buffer overflow vulnerability allows an unauthenticated attacker to execute arbitrary code over the network without user interaction, potentially leading to complete system compromise, data theft, or malware installation.
Technical details
This vulnerability is a heap-based buffer overflow in the Windows RNDIS driver that can be triggered remotely over the network by an unauthenticated attacker. The vulnerability allows arbitrary code execution with system privileges. No authentication or special preconditions are required to exploit this flaw—an attacker can send specially crafted network packets to trigger the overflow. Microsoft has released patches for affected Windows versions through their security update process.
Affected products
- Microsoft Windows RNDIS
Timeline
- 2026-09-08: disclosed