Windows Remote Desktop Services Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-50369Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows Remote Desktop Services allows an authorized attacker to escalate privileges over a network. The attacker must have valid user credentials to exploit this flaw, which affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures.

What this means
What could happen
An attacker with a valid user account on a Windows system running Remote Desktop Services could exploit a use-after-free flaw to run commands with elevated privileges, potentially gaining full control of the affected machine. For OT environments, this means an attacker with compromised operator credentials could escalate to administrative access and alter industrial control system settings or shut down critical services.
Who's at risk
Windows administrators and OT facility personnel who use Remote Desktop Services to manage Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems, including HMI workstations, data historian servers, and Windows-based industrial PCs. This impacts any facility where RDS is used for remote operations or engineering access.
How it could be exploited
An attacker must first obtain valid credentials for a user account on the Windows system (e.g., through phishing, credential theft, or a compromised HMI workstation). They then connect via Remote Desktop Services and trigger the use-after-free vulnerability in the RDS service memory handling. This allows the attacker to execute arbitrary commands with administrator-level privileges on the same machine.
Prerequisites
  • Valid Windows domain or local user credentials
  • Network access to Remote Desktop Services (TCP port 3389 or configured RDP port)
  • Windows system must have RDS enabled
remotely exploitablerequires valid credentialsaffects Windows servers used in industrial environmentshigh CVSS score (8.8)moderate exploit probability (0.7% EPSS)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to Remote Desktop Services (port 3389 or configured RDP port) to authorized management networks only using firewall rules
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-July security update to all affected Windows 10, Windows 11, and Windows Server systems
HARDENINGEnable Network Level Authentication (NLA) on RDS to require authentication before establishing a session
Long-term hardening
0/1
HARDENINGImplement multi-factor authentication (MFA) for remote access to systems with RDS enabled
API: /api/v1/advisories/907eaeca-a055-459f-b971-c9feadd3aa32

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Services Elevation of Privilege Vulnerability | CVSS 8.8 - OTPulse