Windows Remote Desktop Services Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-58626Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows Remote Desktop Services allows an authenticated attacker to execute arbitrary code remotely. The vulnerability affects Windows Server 2022, Windows Server 2025, Windows 10 (21H2, 22H2), and Windows 11 (24H2, 25H2, 26H1) across x64, ARM64, and 32-bit architectures. Exploitation requires valid RDS credentials and network access to the RDS service.
What this means
What could happen
An authenticated attacker could execute arbitrary code on your server or workstation through Remote Desktop Services (RDS), potentially gaining full system control and compromising any data or processes running on that machine.
Who's at risk
IT administrators and operators managing Windows Server 2022, 2025, or Windows 10/11 systems that have Remote Desktop Services enabled or exposed to network access. This includes server environments using RDS for remote management and any workstations exposed to RDP connections from outside your organization.
How it could be exploited
An attacker with valid RDS credentials connects to the RDS service and sends a crafted request that triggers a use-after-free memory vulnerability in the RDS code. This allows the attacker to execute commands with the privileges of the RDS service, typically system or administrator level.
Prerequisites
- Valid Remote Desktop Services credentials (domain account or local user)
- Network access to RDS port (typically TCP 3389)
- RDS service enabled and listening on the target machine
remotely exploitablerequires authenticationaffects multiple Windows versionshigh CVSS score
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDRestrict network access to RDS port 3389 using firewall rules to only allow connections from trusted administrative networks or jump hosts
HARDENINGDisable RDS on systems that do not require remote access
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXUpdate all Windows Server and Windows client systems to July 2026 security updates: Windows Server 2022 to Build 10.0.20348.5386 or later, Windows Server 2025 to Build 10.0.26100.33158 or later, Windows 10 to Build 10.0.19044.7548 (21H2) or 10.0.19045.7548 (22H2) or later, Windows 11 to Build 10.0.26100.8875 (24H2/25H2) or 10.0.28000.2525 (26H1) or later
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate RDS-enabled systems from untrusted networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/07b29c87-0922-4267-a960-7878f1e6942cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.