Windows Remote Desktop Services Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-58626Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows Remote Desktop Services allows an authenticated attacker to execute arbitrary code remotely. The vulnerability affects Windows Server 2022, Windows Server 2025, Windows 10 (21H2, 22H2), and Windows 11 (24H2, 25H2, 26H1) across x64, ARM64, and 32-bit architectures. Exploitation requires valid RDS credentials and network access to the RDS service.

What this means
What could happen
An authenticated attacker could execute arbitrary code on your server or workstation through Remote Desktop Services (RDS), potentially gaining full system control and compromising any data or processes running on that machine.
Who's at risk
IT administrators and operators managing Windows Server 2022, 2025, or Windows 10/11 systems that have Remote Desktop Services enabled or exposed to network access. This includes server environments using RDS for remote management and any workstations exposed to RDP connections from outside your organization.
How it could be exploited
An attacker with valid RDS credentials connects to the RDS service and sends a crafted request that triggers a use-after-free memory vulnerability in the RDS code. This allows the attacker to execute commands with the privileges of the RDS service, typically system or administrator level.
Prerequisites
  • Valid Remote Desktop Services credentials (domain account or local user)
  • Network access to RDS port (typically TCP 3389)
  • RDS service enabled and listening on the target machine
remotely exploitablerequires authenticationaffects multiple Windows versionshigh CVSS score
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict network access to RDS port 3389 using firewall rules to only allow connections from trusted administrative networks or jump hosts
HARDENINGDisable RDS on systems that do not require remote access
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXUpdate all Windows Server and Windows client systems to July 2026 security updates: Windows Server 2022 to Build 10.0.20348.5386 or later, Windows Server 2025 to Build 10.0.26100.33158 or later, Windows 10 to Build 10.0.19044.7548 (21H2) or 10.0.19045.7548 (22H2) or later, Windows 11 to Build 10.0.26100.8875 (24H2/25H2) or 10.0.28000.2525 (26H1) or later
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate RDS-enabled systems from untrusted networks
API: /api/v1/advisories/07b29c87-0922-4267-a960-7878f1e6942c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Services Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse