ZeroHour

CVE-2026-21533

KEVmass1

Local Privilege Escalation in Windows Remote Desktop (CVE-2026-21533)

CISA: Microsoft Windows Improper Privilege Management Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

An improper privilege management flaw (CWE-269) in Windows Remote Desktop allows an authorized attacker who already holds a low-privileged account on a system to elevate privileges locally, with no user interaction required. Successful exploitation carries a high impact on confidentiality, integrity and availability, effectively granting the attacker elevated (SYSTEM-level) control of the compromised host. The flaw affects a broad range of Windows 10 and Windows 11 client builds and Windows Server releases from 2012 through 2022 23H2. It was fixed in Microsoft's February 2026 Patch Tuesday release and is one of six actively exploited zero-days patched that month. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild; whether ransomware operators are leveraging it is unknown.

What to do: Apply Microsoft's February 2026 Patch Tuesday security updates immediately across all listed Windows 10/11 and Windows Server builds, prioritizing RDP-enabled servers, shared workstations and hosts where low-privileged users are common; federal agencies must follow BOD 22-01 timelines per the CISA KEV entry. Because any low-privileged local access is sufficient for full host takeover, treat unpatched endpoints as high-risk in intrusion investigations and hunt for signs of post-compromise privilege escalation. Follow vendor mitigations as instructed by CISA's required action, since no public workaround or PoC is documented.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2
Microsoft Windows Server2012, 2016, 2019, 2022, 2022 23H2
Estimated exposure
mass>1 billion Windows devices (essentially the entire current Windows 10/11 client and Windows Server 2012-2022 installed base) — Windows holds roughly 70% share of a global desktop installed base measured in over a billion devices and Windows Server 2012 through 2022 remains widely deployed in enterprises, and the affected versions span all current supported builds;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news