Windows Remote Desktop Services Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69287Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Use-after-free vulnerability in Windows Remote Desktop Services allows an authorized local user to elevate their privileges to system level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (all recent versions), and Windows Server 2016 through 2025. Microsoft has released patches for all affected versions and recommends applying the September 2026 security update.

What this means
What could happen
An attacker with a local user account on a Windows system running Remote Desktop Services could exploit this vulnerability to run commands with system privileges, potentially gaining control of the entire machine. This is particularly risky if the system manages critical infrastructure like water treatment processes or power distribution.
Who's at risk
Windows system administrators and OT operators who rely on Windows 10 or Windows Server systems (2016, 2019, 2022, 2025) for HMI (Human Machine Interface) workstations, engineering stations, or OPC servers. Any water authority or utility using Windows-based SCADA clients, historian servers, or control system interfaces should prioritize this patch to prevent unauthorized privilege escalation that could lead to process manipulation.
How it could be exploited
An attacker with local user credentials on the system would trigger a use-after-free condition in the Remote Desktop Services component, causing memory corruption that allows privilege escalation from a regular user to system/SYSTEM level. This requires the attacker to already have valid login credentials on the Windows machine.
Prerequisites
  • Local user account credentials (standard or administrative account)
  • Physical access or remote access (such as RDP, SSH, or VPN) to log into the Windows machine
  • The Windows system must be running one of the affected versions listed in the advisory
Low complexity exploitationRequires local user account (not remotely exploitable without prior access)Affects Windows systems widely used in industrial control environments
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/10
Schedule — requires maintenance window
0/9

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1607 to Build 10.0.14393.9512 or later
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 to the latest patched build for your version (23H2, 24H2, 25H2, or 26H1)
Long-term hardening
0/1
HARDENINGRestrict local login access to Windows systems to only essential personnel; use role-based access controls to limit who can have user accounts on these machines
API: /api/v1/advisories/882977ca-8162-4049-875e-d7b6eff162a3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Remote Desktop Services Elevation of Privilege Vulnerability | CVSS 7 - OTPulse