CVE-2026-69287
massUse-After-Free Local Privilege Escalation in Windows Remote Desktop Services
CVE-2026-69287 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Windows Remote Desktop Services, reported and coordinated by Microsoft. An authorized attacker—meaning an attacker who already holds a valid low-privileged session on the host—triggers the flaw by causing RDS to reuse freed memory under conditions that make the bug hard to reliably reach (CVSS attack complexity is high, and the attack vector is local). Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.0, High). Any Windows deployment where Remote Desktop Services is enabled is potentially affected, though the source data does not specify exact affected Windows versions or builds. As of this analysis there is no public proof-of-concept, no known exploitation in the wild, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at only 0.3% (17th percentile).
What to do: Patch via Windows Update per Microsoft's advisory as soon as the affected version list is published, prioritizing multi-user hosts where the Remote Desktop Services role (RDS/Session Host) or Remote Desktop is enabled. Until patched, restrict RDS/RDP access to trusted, low-privilege accounts and audit which servers expose Remote Desktop sessions. There is no public PoC or KEV entry yet, so treat this as a standard-severity local hardening item rather than an emergency, but verify patch coverage across the estate.
| Microsoft Windows Remote Desktop Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.