CVE-2026-69539
massUse-After-Free RCE in Microsoft Windows Remote Desktop Services
CVE-2026-69539 is a use-after-free memory-corruption vulnerability (CWE-416) in Microsoft's Windows Remote Desktop Services. It is triggered over the network by traffic processed by the RDS service under high-attack-complexity conditions, and the attacker must already possess valid low-privileged ('authorized') credentials; no user interaction is required. Successful exploitation yields remote code execution in the context of the service, with high impact on confidentiality, integrity, and availability. Any Windows system with the Remote Desktop Services role enabled — especially internet-exposed RDP endpoints — is potentially affected; Microsoft's advisory enumerates the specific affected Windows releases. As of this writing there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.5% probability of exploitation within 30 days (42nd percentile), so no exploitation is known.
What to do: Apply Microsoft's security update for this CVE as soon as it is available, checking the Microsoft advisory for the patched builds corresponding to your Windows releases (version numbers are not provided in this data). Until patched, restrict RDP/RDS exposure behind a VPN or RD Gateway, enforce Network Level Authentication and MFA, and audit which accounts hold remote logon rights, since exploitation requires valid credentials. Prioritize remediation on internet-facing RDS hosts.
| Microsoft Windows (Remote Desktop Services component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.