Remote Desktop Licensing Service Elevation of Privilege Vulnerability
Plan PatchCVSS 7.1CVE-2026-68893Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
Use-after-free vulnerability in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. This affects Windows 10 (versions 1607 and 1809) and Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An attacker with local or network access to a Windows Server running Remote Desktop Licensing Service could gain system-level privileges, potentially allowing them to take control of the server and any connected systems or data.
Who's at risk
Windows Server administrators and organizations using Remote Desktop Licensing on Windows 10 or Windows Server 2016/2019/2022/2025. This affects any environment where Remote Desktop Services licensing is deployed, including hybrid environments with on-premises servers.
How it could be exploited
An attacker with valid user credentials would connect to the Remote Desktop Licensing Service over the network. By sending a specially crafted request, they could trigger the use-after-free condition, causing memory corruption that allows privilege escalation to system level.
Prerequisites
- Valid user credentials (local or domain account)
- Network or local access to Windows Server with Remote Desktop Licensing Service enabled
- Ability to interact with the Remote Desktop Licensing Service
Requires authenticationRequires user interaction or specific conditionsRemotely exploitableAffects server infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/7
Do now
0/1HARDENINGRestrict network access to Remote Desktop Licensing Service ports to authorized administrative systems only
Schedule — requires maintenance window
0/6Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 (including Server Core) to Build 10.0.17763.9245 or later via Windows Update
Windows Server 2022
HOTFIXUpdate Windows Server 2022 (including Server Core) to Build 10.0.20348.5622 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (including Server Core) to Build 10.0.26100.33438 or later via Windows Update
Windows Server 2016
HOTFIXUpdate Windows Server 2016 (including Server Core) to Build 10.0.14393.9512 or later via Windows Update
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later via Windows Update
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9512 or later via Windows Update
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/3073d604-cc14-438d-a911-c7c6c5468aeaGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.