ZeroHour

CVE-2026-69338

large

Use-After-Free Privilege Escalation in Microsoft Remote Desktop Gateway Service

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69338 is a use-after-free memory corruption flaw (CWE-416) in the Microsoft Remote Desktop Gateway Service, the Windows Server role that brokers authenticated RDP connections over HTTPS. An authorized attacker with low-level credentials must send specially crafted network traffic to the gateway under conditions that require user interaction and high attack complexity, per the CVSS vector, meaning exploitation likely involves careful timing or state manipulation to trigger the freed-memory reuse. Successful exploitation yields local-or-service-context elevation of privilege on the gateway host with high confidentiality, integrity, and availability impact. The flaw affects organizations running the RD Gateway role on Windows Server; the affected version ranges are not listed in the available data, so defenders should consult Microsoft's advisory for the exact product/version matrix. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS is 0.5%, indicating no known active exploitation.

What to do: Check whether the RD Gateway role is installed (Server Manager or Get-WindowsFeature RDS-Gateway) and apply Microsoft's security update for your Windows Server versions as soon as it is available, since no version matrix is present in the available data. Until patched, minimize exposure by restricting RD Gateway (typically 443/3389) to required source networks or placing it behind a VPN, and review gateway authentication/authorization policies and logs for anomalous authenticated sessions. Given the authenticated, high-complexity preconditions and zero known exploitation, this is a routine-priority patch item for exposed gateways rather than an emergency.

Affected
Microsoft Remote Desktop Gateway Service (Windows Server role)
Estimated exposure
largetens of thousands of internet-exposed RD Gateway servers, with additional unexposed internal deployments — RD Gateway is an opt-in Windows Server role rather than a default service, and public internet scans (e.g., Shodan/Censys) typically surface tens of thousands of exposed RD Gateway/RD Web endpoints, putting internet-exposed systems in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.