CVE-2026-80096
massOut-of-bounds Read Elevation-of-Privilege Flaw in Windows Remote Desktop Services
CVE-2026-80096 is an out-of-bounds read (CWE-125) in Microsoft Windows Remote Desktop Services (RDS), the component that provides remote graphical sessions on Windows hosts. An attacker who already holds low-privileged, authorized access can trigger the flaw by sending crafted input to the RDS service over the network, causing the service to read beyond the bounds of an allocated memory buffer. Successful exploitation allows the attacker to elevate privileges on the target host, and the CVSS vector (AV:N/AC:L/PR:L/UI:N with high confidentiality, integrity, and availability impact) rates the issue 8.8 (High). Any Windows system with Remote Desktop Services enabled is potentially affected, though Microsoft has not published affected version details in the data available here. There is currently no evidence of exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.7% (52nd percentile).
What to do: Apply Microsoft's security update for CVE-2026-80096 via Windows Update/WSUS or the Microsoft advisory as soon as practical, prioritizing hosts running the Remote Desktop Services role or with RDP enabled. Inventory RDP exposure by checking for RDS-enabled systems and TCP/3389 listeners, and restrict internet-facing RDP (VPN, firewall rules, Network Level Authentication) as an interim mitigation. Monitor Microsoft's advisory for affected-version specifics and any updated guidance.
| Microsoft Windows Remote Desktop Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.