{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "authz_bypass",
  "claimed_impact_class": "authz_bypass",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "Unauthenticated RFB 3.8 handshake selecting security type None over Xvnc's unintended localhost TCP listener",
  "trigger_path": "xrdp-sesrun Xvnc-UDS session creation -> xrdp-sesman -> xrdp-sesexec -> Xvnc TCP RFB listener -> unauthenticated ServerInit",
  "claimed_surface": "network_protocol",
  "validated_surface": "network_protocol",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": false,
  "exploit_chain_demonstrated": true,
  "accepted_exploit_knowledge_record_ids": [
    "0a84fef6-73ac-4e47-8e1e-0b59d1237c17"
  ],
  "inferred": false
}
