The vulnerability exists due to a null pointer dereference flaw inside the DCERPC protocol parser. The engine fails to verify object creation success when handling uncommon transaction types, causing a direct application crash if a stub reference is called on a failed structure allocation.