ZeroHour

CVE-2026-69536

mass

Use-After-Free RCE in Microsoft Windows Remote Desktop Services

CVSS 3.1
7.1 high
EPSS
<1%p37
Published
()
Modified
AI analysis

Windows Remote Desktop Services contains a use-after-free memory-safety flaw (CWE-416) that Microsoft rates High severity (CVSS 7.1). An authorized attacker — one holding at least low-privilege credentials — can trigger the flaw over a network by sending crafted input to the RDS service, though the CVSS vector's high attack complexity and required user interaction indicate exploitation is not straightforward. Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact in the context of the affected system. Any Windows host running Remote Desktop Services, such as RD Session Hosts or other servers accepting remote desktop connections, is potentially affected; the available data does not specify affected version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69536 through Windows Update as soon as it is available, prioritizing internet-facing RD Session Hosts and multi-user servers. Until patched, reduce exposure by requiring valid credentials via VPN or RD Gateway, enforcing Network Level Authentication and MFA, and firewalling RDP from direct internet access. Because exploitation requires an authorized account, review which accounts can reach RDS endpoints and check for exposed or weakly credentialed RDP listeners.

Affected
Microsoft Windows Remote Desktop Services
Estimated exposure
massmillions of Windows hosts with RDS/RDP enabled, likely on the order of a few million internet-exposed RDP endpoints — Internet-wide scans of RDP (port 3389) routinely index millions of exposed Windows hosts, and Remote Desktop Services is widely deployed in enterprise terminal-server, VDI, and remote-administration scenarios, so the potentially affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.