ZeroHour

CVE-2026-69292

large

Double Free in Microsoft Remote Desktop Gateway Allows Local Privilege Elevation

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-69292 is a double-free memory-corruption flaw (CWE-415) in the Microsoft Remote Desktop Gateway Service, assigned by Microsoft's CNA and rated CVSS 7.0 (High) with a local attack vector and high exploit complexity. An attacker who already holds an authorized, low-privileged account on the affected system can trigger the double free and elevate privileges within the service's context, with high impact to confidentiality, integrity, and availability; because RD Gateway is a privileged Windows service, this typically yields full local control. Only systems where the Remote Desktop Gateway role/service is installed are affected, most commonly Windows Servers deployed as remote-access gateways for RDP over HTTPS; the source data does not enumerate specific Windows versions. There is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days (10th percentile), so no in-the-wild exploitation is known.

What to do: Inventory Windows Servers with the Remote Desktop Gateway role and apply Microsoft's security update for CVE-2026-69292 when released; since specific affected versions are not in this data, track Microsoft's advisory for exact version and KB details. Until patched, restrict local logon and RDP access on RD Gateway servers to trusted users, prioritizing multi-tenant or VDI-adjacent gateways where less-trusted accounts hold local access.

Affected
Microsoft Remote Desktop Gateway Service (Remote Desktop Gateway role on Windows)
Estimated exposure
largetens of thousands of RD Gateway servers worldwide (est.), each serving multiple authenticated users — Public internet scans of RDP-over-HTTPS/RD Gateway endpoints and the role's common deployment as an enterprise remote-access entry point suggest deployments on the order of tens of thousands of servers, though exact published counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.