CVE-2026-68893
largeUse-After-Free Privilege Escalation in Microsoft Windows Remote Desktop Licensing Service
CVE-2026-68893 is a use-after-free memory-safety flaw (CWE-416) in the Windows Remote Desktop Licensing Service, disclosed by Microsoft. An attacker who already has low-privileged credentials on the network can send crafted licensing traffic to the service and, given the high attack complexity and required user interaction, trigger the use-after-free condition. Successful exploitation lets the attacker elevate privileges on the affected host, with high impact on confidentiality, integrity, and availability of that system. Affected organizations are those running Windows hosts with the Remote Desktop Licensing service/role enabled, typically the RD Licensing servers in enterprise Remote Desktop Services deployments. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.5%, so no confirmed exploitation has been reported yet.
What to do: Apply Microsoft's security update for CVE-2026-68893 across affected Windows releases as soon as it is available, prioritizing servers with the Remote Desktop Licensing role (RDS license servers). Until patched, restrict network access to hosts running the licensing service to trusted administrative segments and inventory which servers have the role installed via Server Manager or your configuration-management tooling.
| Microsoft Windows Remote Desktop Licensing Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.