ZeroHour

CVE-2026-69599

mass

Use-After-Free RCE in Windows Remote Desktop Services

CVSS 3.1
7.5 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-69599 is a use-after-free (CWE-416) in Microsoft's Windows Remote Desktop Services, a memory-corruption flaw in which memory that has been freed is referenced during RDS processing. An authorized user with low privileges can trigger it over the network, though the high attack complexity means successful exploitation depends on favorable memory-layout conditions rather than a straightforward one-shot request. A successful exploit yields remote code execution, with high impact on confidentiality, integrity, and availability. Any Windows system with Remote Desktop Services (or RDP) enabled is potentially affected, especially servers accepting remote connections from multiple users. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently assigns a 0.7% probability of exploitation within 30 days (50th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69599 through Windows Update/WSUS as soon as it is released, prioritizing internet-facing hosts running the Remote Desktop Services role. As interim mitigation, restrict RDP exposure to VPNs or trusted networks, enforce Network Level Authentication, and limit remote-access accounts. Inventory your estate for systems with RDS/RDP enabled to scope patching, since exploitation requires an authorized user rather than an unauthenticated attacker.

Affected
Microsoft Windows Remote Desktop Services
Estimated exposure
mass≈3–4 million internet-exposed RDP/RDS endpoints (public scan data); exploitation additionally requires an authorized account — Public internet scans have long shown millions of RDP endpoints exposed to the internet and RDP/RDS is commonly enabled on Windows servers, though this flaw only applies where a remote user holds valid credentials.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.