Windows Remote Desktop Services Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-61356Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized local attacker to elevate privileges to SYSTEM level. This affects Windows 10, Windows 11, Windows Server 2019, 2022, and 2025.

What this means
What could happen
A user with local access to a Windows system running RDS could escalate their privileges to SYSTEM, potentially gaining control over that computer and any connected OT devices or industrial control systems it manages.
Who's at risk
Any organization using Windows 10, Windows 11, Windows Server 2019, 2022, or 2025 as HMI (Human Machine Interface) systems, engineering workstations, or server infrastructure that interfaces with industrial processes. This includes OT networks using Windows-based SCADA/MES clients, historian servers, or data aggregation systems.
How it could be exploited
An attacker with a standard user account on the affected system can exploit missing authentication checks in Remote Desktop Services to escalate to SYSTEM-level privileges without additional user interaction. This could be leveraged to modify device configurations, access sensitive files, or laterally move to other systems on the network.
Prerequisites
  • Local user account on the affected Windows system
  • No special privileges required for initial access
Elevation of privilege possibleLow attack complexityAuthentication bypass in security-critical component
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 Windows security update to all Windows 10, 11, and Server systems
Long-term hardening
0/2
HARDENINGRestrict local user access: Disable unnecessary local accounts and enforce strong password policies
HARDENINGApply Windows privilege access management (PAM): Use account tiering to limit which users can log on locally to critical OT systems
API: /api/v1/advisories/1840f46c-08c9-4ea5-9176-99c0ff45b9ff

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Services Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse