CVE-2026-21533
KEVmass1Local Privilege Escalation in Windows Remote Desktop (CVE-2026-21533)
CISA: Microsoft Windows Improper Privilege Management Vulnerability
An improper privilege management flaw (CWE-269) in Windows Remote Desktop allows an authorized attacker who already holds a low-privileged account on a system to elevate privileges locally, with no user interaction required. Successful exploitation carries a high impact on confidentiality, integrity and availability, effectively granting the attacker elevated (SYSTEM-level) control of the compromised host. The flaw affects a broad range of Windows 10 and Windows 11 client builds and Windows Server releases from 2012 through 2022 23H2. It was fixed in Microsoft's February 2026 Patch Tuesday release and is one of six actively exploited zero-days patched that month. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild; whether ransomware operators are leveraging it is unknown.
What to do: Apply Microsoft's February 2026 Patch Tuesday security updates immediately across all listed Windows 10/11 and Windows Server builds, prioritizing RDP-enabled servers, shared workstations and hosts where low-privileged users are common; federal agencies must follow BOD 22-01 timelines per the CISA KEV entry. Because any low-privileged local access is sufficient for full host takeover, treat unpatched endpoints as high-risk in intrusion investigations and hunt for signs of post-compromise privilege escalation. Follow vendor mitigations as instructed by CISA's required action, since no public workaround or PoC is documented.
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 23H2, 24H2, 25H2 |
| Microsoft Windows Server | 2012, 2016, 2019, 2022, 2022 23H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H