Windows Remote Desktop Services Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-61364Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A missing authentication check in Windows Remote Desktop Services allows an authorized local user to escalate privileges to SYSTEM level without additional credentials. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across all architectures. Exploitation is assessed as Less Likely. Microsoft has released patches for all affected versions.
What this means
What could happen
An authorized user logged into a Windows workstation or server could escalate their privileges to system level, allowing them to modify system settings, access all files, and potentially interfere with any running services including SCADA systems or operator interfaces relying on Remote Desktop Services.
Who's at risk
Any Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 system running Remote Desktop Services that is used by engineers, operators, or IT staff to manage control systems, SCADA interfaces, or other OT equipment. This includes both dedicated servers and workstations that provide remote administration capabilities to field devices or process control systems.
How it could be exploited
An attacker with a valid user account on the affected Windows system could exploit a missing authentication check in Remote Desktop Services to escalate privileges without additional credentials or interaction. Once escalated to system level, the attacker can run arbitrary commands with full system access.
Prerequisites
- Valid user account on the Windows system (domain or local)
- Ability to interact with Remote Desktop Services on the local system or via RDP session
Local privilege escalation requires valid credentialsAffects multiple Windows versionsAll supported versions have patches availableRemote Desktop is common in ICS/OT remote management scenarios
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict Remote Desktop Services access to only authorized personnel and networks using firewall rules on port 3389
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Windows security update for your version (Build 10.0.17763.9115 for Server 2019, 10.0.20348.5499 for Server 2022, 10.0.26100.33296 for Server 2025, or appropriate client OS build number)
Long-term hardening
0/1HARDENINGEnforce strong password policies and multi-factor authentication for all accounts that can access RDP
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fd147a66-58ef-47aa-ab65-71de3ef366bbGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.