CVE-2026-69599
massUse-After-Free RCE in Windows Remote Desktop Services
CVE-2026-69599 is a use-after-free (CWE-416) in Microsoft's Windows Remote Desktop Services, a memory-corruption flaw in which memory that has been freed is referenced during RDS processing. An authorized user with low privileges can trigger it over the network, though the high attack complexity means successful exploitation depends on favorable memory-layout conditions rather than a straightforward one-shot request. A successful exploit yields remote code execution, with high impact on confidentiality, integrity, and availability. Any Windows system with Remote Desktop Services (or RDP) enabled is potentially affected, especially servers accepting remote connections from multiple users. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently assigns a 0.7% probability of exploitation within 30 days (50th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69599 through Windows Update/WSUS as soon as it is released, prioritizing internet-facing hosts running the Remote Desktop Services role. As interim mitigation, restrict RDP exposure to VPNs or trusted networks, enforce Network Level Authentication, and limit remote-access accounts. Inventory your estate for systems with RDS/RDP enabled to scope patching, since exploitation requires an authorized user rather than an unauthenticated attacker.
| Microsoft Windows Remote Desktop Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.