Windows Remote Desktop Services Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-61367Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A missing authentication check in Windows Remote Desktop Services allows a user with a valid local or RDP account to elevate their privileges to system administrator level without authorization. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, and 22H2), Windows 11 (versions 23H2, 24H2, and 25H2), and Windows Server 2016, 2019, 2022, and 2025 across all system architectures. Microsoft has released fixes for all affected versions; exploitation is considered less likely in practice.
What this means
What could happen
An attacker with a local user account on a Windows server running Remote Desktop Services could elevate their privileges to administrator level, allowing them to control the entire system and any industrial processes running on it.
Who's at risk
Windows system administrators and OT personnel who manage Windows Server 2016, 2019, 2022, and 2025 installations, as well as any Windows 10 or 11 workstations running Remote Desktop Services. This is especially critical for HMI (Human-Machine Interface) servers, engineering workstations, and any Windows-based control system components in water utilities or power systems.
How it could be exploited
An attacker with valid login credentials to a Windows server runs a specially crafted command or script locally, bypassing authentication checks in Remote Desktop Services to gain administrator privileges. This requires interactive access to the machine itself or through an RDP session with a low-privileged account.
Prerequisites
- Valid local or RDP user account on the affected Windows system
- Local or remote interactive access to the Windows system
Local privilege escalationRequires valid user credentialsLow attack complexityAffects Windows control system components
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict RDP access to engineering workstations and administrative systems only, blocking RDP ports (default 3389) from untrusted networks at the firewall
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the August 2026 Microsoft security update to all affected Windows systems (Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025)
Long-term hardening
0/2HARDENINGDisable unnecessary Remote Desktop Services instances on servers that do not require RDP access
HARDENINGRequire multi-factor authentication (MFA) for all RDP connections to reduce risk of unauthorized account access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/af960075-3db3-4377-a20f-eb7b30490c52Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.