Skip to finding
important · Physical — Windows RNDIS

Unauthenticated RNDIS traffic can execute code across supported Windows releases, but the physical-versus-routed boundary is undisclosed.

Affects

Supported Windows desktop and server releases implementing RNDIS, Microsoft's network-device protocol commonly associated with USB peripherals and tethering.

Malformed input reaching an active RNDIS interface can trigger a heap overflow and execute code on the Windows host.

Detail and 2 sources

We do not know whether the cheapest attacker position is a routed peer, a LAN peer or a malicious attached or tethered device.

Chain to watch
Reach an active Windows RNDIS interface without authentication→↓Send malformed RNDIS input that triggers the heap overflow→↓Execute code on the Windows host→↓The public record does not establish whether delivery is routed, local-network or attached-device access.
Unverified chainRead a detailed MSRC or CSAF record or diff the fixed RNDIS driver, then test routed and attached delivery separately.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026