CVE-2026-69536
massUse-After-Free RCE in Microsoft Windows Remote Desktop Services
Windows Remote Desktop Services contains a use-after-free memory-safety flaw (CWE-416) that Microsoft rates High severity (CVSS 7.1). An authorized attacker — one holding at least low-privilege credentials — can trigger the flaw over a network by sending crafted input to the RDS service, though the CVSS vector's high attack complexity and required user interaction indicate exploitation is not straightforward. Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact in the context of the affected system. Any Windows host running Remote Desktop Services, such as RD Session Hosts or other servers accepting remote desktop connections, is potentially affected; the available data does not specify affected version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69536 through Windows Update as soon as it is available, prioritizing internet-facing RD Session Hosts and multi-user servers. Until patched, reduce exposure by requiring valid credentials via VPN or RD Gateway, enforcing Network Level Authentication and MFA, and firewalling RDP from direct internet access. Because exploitation requires an authorized account, review which accounts can reach RDS endpoints and check for exposed or weakly credentialed RDP listeners.
| Microsoft Windows Remote Desktop Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.