Remote Desktop Licensing Service Elevation of Privilege Vulnerability

Plan PatchCVSS 7.1CVE-2026-68893Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary

Use-after-free vulnerability in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. This affects Windows 10 (versions 1607 and 1809) and Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker with local or network access to a Windows Server running Remote Desktop Licensing Service could gain system-level privileges, potentially allowing them to take control of the server and any connected systems or data.
Who's at risk
Windows Server administrators and organizations using Remote Desktop Licensing on Windows 10 or Windows Server 2016/2019/2022/2025. This affects any environment where Remote Desktop Services licensing is deployed, including hybrid environments with on-premises servers.
How it could be exploited
An attacker with valid user credentials would connect to the Remote Desktop Licensing Service over the network. By sending a specially crafted request, they could trigger the use-after-free condition, causing memory corruption that allows privilege escalation to system level.
Prerequisites
  • Valid user credentials (local or domain account)
  • Network or local access to Windows Server with Remote Desktop Licensing Service enabled
  • Ability to interact with the Remote Desktop Licensing Service
Requires authenticationRequires user interaction or specific conditionsRemotely exploitableAffects server infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Do now
0/1
HARDENINGRestrict network access to Remote Desktop Licensing Service ports to authorized administrative systems only
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 (including Server Core) to Build 10.0.17763.9245 or later via Windows Update
Windows Server 2022
HOTFIXUpdate Windows Server 2022 (including Server Core) to Build 10.0.20348.5622 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (including Server Core) to Build 10.0.26100.33438 or later via Windows Update
Windows Server 2016
HOTFIXUpdate Windows Server 2016 (including Server Core) to Build 10.0.14393.9512 or later via Windows Update
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later via Windows Update
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9512 or later via Windows Update
API: /api/v1/advisories/3073d604-cc14-438d-a911-c7c6c5468aea

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Licensing Service Elevation of Privilege Vulnerability | CVSS 7.1 - OTPulse