ZeroHour

CVE-2026-69475

mass

Untrusted Pointer Dereference Privilege Escalation in Windows Remote Desktop Services

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69475 is an untrusted pointer dereference (CWE-822) in Windows Remote Desktop Services, in which code dereferences a pointer to memory it does not reliably validate. It is triggered locally: an attacker who is already authorized to log on to the machine with low privileges can reach the vulnerable Remote Desktop Services code path without any user interaction. A successful exploit elevates the attacker's privileges on that host, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). Affected organizations are those running Windows systems with Remote Desktop Services enabled — most notably multi-user RDS session hosts and published-desktop/application servers, plus any Windows machine granting RDP logon to untrusted users — although the CVE record does not enumerate specific Windows versions, so Microsoft's advisory should be consulted for affected builds. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation within 30 days, so it is not currently known to be exploited in the wild.

What to do: Apply Microsoft's security update addressing CVE-2026-69475 to all Windows systems with Remote Desktop Services or RDP enabled, prioritizing multi-user RDS session hosts and published-desktop servers where low-privileged users can log on and run code. Until patched, limit which accounts may log on locally or via RDP to these systems and watch for anomalous privilege-escalation activity, keeping in mind the low EPSS score does not rule out future weaponization. Track Microsoft's advisory for the exact affected version ranges, since the CVE record does not list specific builds.

Affected
Microsoft Windows Remote Desktop Services
Estimated exposure
massmillions of RDP/RDS-enabled Windows systems (public internet-wide scans report multi-million counts of RDP-listening hosts) — Internet-wide scans such as Shodan consistently find millions of Windows hosts listening on RDP, and RDP is served by the same Remote Desktop Services component, though the subset running full RDS role deployments is not quantified, making…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.