CVE-2026-69475
massUntrusted Pointer Dereference Privilege Escalation in Windows Remote Desktop Services
CVE-2026-69475 is an untrusted pointer dereference (CWE-822) in Windows Remote Desktop Services, in which code dereferences a pointer to memory it does not reliably validate. It is triggered locally: an attacker who is already authorized to log on to the machine with low privileges can reach the vulnerable Remote Desktop Services code path without any user interaction. A successful exploit elevates the attacker's privileges on that host, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). Affected organizations are those running Windows systems with Remote Desktop Services enabled — most notably multi-user RDS session hosts and published-desktop/application servers, plus any Windows machine granting RDP logon to untrusted users — although the CVE record does not enumerate specific Windows versions, so Microsoft's advisory should be consulted for affected builds. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation within 30 days, so it is not currently known to be exploited in the wild.
What to do: Apply Microsoft's security update addressing CVE-2026-69475 to all Windows systems with Remote Desktop Services or RDP enabled, prioritizing multi-user RDS session hosts and published-desktop servers where low-privileged users can log on and run code. Until patched, limit which accounts may log on locally or via RDP to these systems and watch for anomalous privilege-escalation activity, keeping in mind the low EPSS score does not rule out future weaponization. Track Microsoft's advisory for the exact affected version ranges, since the CVE record does not list specific builds.
| Microsoft Windows Remote Desktop Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-822
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.