CVE-2026-69338
largeUse-After-Free Privilege Escalation in Microsoft Remote Desktop Gateway Service
CVE-2026-69338 is a use-after-free memory corruption flaw (CWE-416) in the Microsoft Remote Desktop Gateway Service, the Windows Server role that brokers authenticated RDP connections over HTTPS. An authorized attacker with low-level credentials must send specially crafted network traffic to the gateway under conditions that require user interaction and high attack complexity, per the CVSS vector, meaning exploitation likely involves careful timing or state manipulation to trigger the freed-memory reuse. Successful exploitation yields local-or-service-context elevation of privilege on the gateway host with high confidentiality, integrity, and availability impact. The flaw affects organizations running the RD Gateway role on Windows Server; the affected version ranges are not listed in the available data, so defenders should consult Microsoft's advisory for the exact product/version matrix. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS is 0.5%, indicating no known active exploitation.
What to do: Check whether the RD Gateway role is installed (Server Manager or Get-WindowsFeature RDS-Gateway) and apply Microsoft's security update for your Windows Server versions as soon as it is available, since no version matrix is present in the available data. Until patched, minimize exposure by restricting RD Gateway (typically 443/3389) to required source networks or placing it behind a VPN, and review gateway authentication/authorization policies and logs for anomalous authenticated sessions. Given the authenticated, high-complexity preconditions and zero known exploitation, this is a routine-priority patch item for exposed gateways rather than an emergency.
| Microsoft Remote Desktop Gateway Service (Windows Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.