ZeroHour

CVE-2026-69287

mass

Use-After-Free Local Privilege Escalation in Windows Remote Desktop Services

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69287 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Windows Remote Desktop Services, reported and coordinated by Microsoft. An authorized attacker—meaning an attacker who already holds a valid low-privileged session on the host—triggers the flaw by causing RDS to reuse freed memory under conditions that make the bug hard to reliably reach (CVSS attack complexity is high, and the attack vector is local). Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.0, High). Any Windows deployment where Remote Desktop Services is enabled is potentially affected, though the source data does not specify exact affected Windows versions or builds. As of this analysis there is no public proof-of-concept, no known exploitation in the wild, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at only 0.3% (17th percentile).

What to do: Patch via Windows Update per Microsoft's advisory as soon as the affected version list is published, prioritizing multi-user hosts where the Remote Desktop Services role (RDS/Session Host) or Remote Desktop is enabled. Until patched, restrict RDS/RDP access to trusted, low-privilege accounts and audit which servers expose Remote Desktop sessions. There is no public PoC or KEV entry yet, so treat this as a standard-severity local hardening item rather than an emergency, but verify patch coverage across the estate.

Affected
Microsoft Windows Remote Desktop Services
Estimated exposure
massmass — on the order of millions to tens of millions of Windows systems run RDS/RDP-enabled roles — Windows' installed base is in the hundreds of millions of endpoints and public internet scans index millions of exposed RDP endpoints, so the population of systems with the RDS component plausibly exceeds 1M — though because this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.