CVE-2026-69514
massHeap Buffer Overflow RCE in Microsoft Windows Remote Desktop Services
CVE-2026-69514 is a heap-based buffer overflow (CWE-122) in Microsoft Windows Remote Desktop Services that can be triggered remotely over the network. Exploitation requires the attacker to already hold valid low-privileged credentials (an 'authorized attacker') and involves high attack complexity, but no user interaction. A successful attack lets the attacker execute code on the Remote Desktop Services host, with high impact on confidentiality, integrity and availability. Any organization running the affected Windows releases with RDS/RDP enabled is potentially exposed, though the available data does not enumerate specific vulnerable version ranges (see Microsoft's advisory for the authoritative list). Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS places the 30-day exploitation probability at a median 0.7%.
What to do: Apply Microsoft's security update for this CVE via your standard Windows servicing channel (Windows Update/WSUS/SCCM) and check Microsoft's advisory to confirm which of your Windows builds are listed as affected. Until patched, restrict RDP (TCP 3389) exposure to the internet using VPN or firewall allowlists and require NLA, MFA, and strong credentials, since exploitation requires a valid low-privileged account. Inventory which servers run Remote Desktop Services and are externally reachable so patching can be prioritized there first.
| Microsoft Windows Remote Desktop Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.