This issue is caused due to Microsoft Remote Procedure Call (RPC) client implementation improperly allocates memory while parsing specially crafted RPC responses. An attacker could exploit this vulnerability by convincing a victim to initiate an RPC Call to a maliciously hosted RPC server that is designed to exploit this vulnerability by sending a specially crafted RPC response.
Successfully exploitation of this vulnerability could result in complete compromise of an affected system in the security context of the RPC client application.
The information provided herein is on "as is" basis, without warranty of any kind.