ZeroHour

CVE-2026-69539

mass

Use-After-Free RCE in Microsoft Windows Remote Desktop Services

CVSS 3.1
7.5 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-69539 is a use-after-free memory-corruption vulnerability (CWE-416) in Microsoft's Windows Remote Desktop Services. It is triggered over the network by traffic processed by the RDS service under high-attack-complexity conditions, and the attacker must already possess valid low-privileged ('authorized') credentials; no user interaction is required. Successful exploitation yields remote code execution in the context of the service, with high impact on confidentiality, integrity, and availability. Any Windows system with the Remote Desktop Services role enabled — especially internet-exposed RDP endpoints — is potentially affected; Microsoft's advisory enumerates the specific affected Windows releases. As of this writing there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.5% probability of exploitation within 30 days (42nd percentile), so no exploitation is known.

What to do: Apply Microsoft's security update for this CVE as soon as it is available, checking the Microsoft advisory for the patched builds corresponding to your Windows releases (version numbers are not provided in this data). Until patched, restrict RDP/RDS exposure behind a VPN or RD Gateway, enforce Network Level Authentication and MFA, and audit which accounts hold remote logon rights, since exploitation requires valid credentials. Prioritize remediation on internet-facing RDS hosts.

Affected
Microsoft Windows (Remote Desktop Services component)
Estimated exposure
massseveral million internet-exposed RDP/RDS endpoints, plus unknown additional internal deployments — Internet-wide scans (e.g., Shodan/Censys) routinely index millions of hosts exposing RDP on TCP/3389, and the Remote Desktop Services role is widely enabled on Windows servers, so the plausibly exposed population is in the millions — an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.