Windows Remote Desktop Services Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62692Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow vulnerability in Windows Remote Desktop Services allows an authorized local user to elevate their privileges to system administrator level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches in the August 2026 security update. Exploitation is assessed as less likely in the wild.
What this means
What could happen
An attacker with a local user account on a Windows system running Remote Desktop Services could execute arbitrary code with system privileges, gaining full control of the machine and any processes or data on it.
Who's at risk
Windows system administrators and IT staff who manage machines running Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. This affects any system with Remote Desktop Services enabled, including server operating systems and desktop Windows versions used for remote administration or remote work access.
How it could be exploited
An attacker must have an existing local user account on the affected Windows system. They would interact with the Remote Desktop Services component locally to trigger a heap buffer overflow, which could allow them to elevate their privileges from a standard user to system administrator level.
Prerequisites
- Local user account with login access
- Remote Desktop Services component present and running on the system
Low complexity exploitationRequires local user account (not unauthenticated)Affects multiple Windows versions across broad deployment base
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 security update or later for your Windows version
Long-term hardening
0/2HARDENINGRestrict local user account creation and logon privileges to minimize the number of accounts that can trigger the vulnerability
HARDENINGMonitor and audit local user account activity and privilege escalation attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/849748cd-479a-494d-80df-c06696be3d50Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.