Remote Desktop Gateway Service Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69292Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Double free vulnerability in Remote Desktop Gateway Service memory handling on Windows 10 (versions 1607, 1809), Windows Server 2016, 2019, 2022, and 2025. An authorized local attacker can exploit this flaw to elevate privileges to system level. Exploitation is assessed as unlikely.
What this means
What could happen
An attacker with local access to a Windows system running Remote Desktop Gateway Service could exploit a memory handling flaw to gain system-level privileges, potentially allowing them to control process setpoints, disable safety systems, or halt operations on critical infrastructure systems.
Who's at risk
Windows administrators managing systems with Remote Desktop Gateway Service enabled, particularly in utilities and infrastructure environments where these servers provide remote access to critical systems like SCADA workstations, engineering consoles, or remote facility management stations.
How it could be exploited
An attacker with a local user account on an affected Windows system can trigger a double-free vulnerability in the Remote Desktop Gateway Service memory management. By crafting a specific request or malicious input to the RD Gateway Service running with elevated privileges, the attacker can corrupt memory and execute code with system privileges.
Prerequisites
- Local user account on affected Windows system
- Remote Desktop Gateway Service enabled and running
- Windows 10 (versions 1607, 1809), Windows Server 2016, 2019, 2022, or 2025
Requires local account access (insider threat or lateral movement risk)Low exploit complexityHigh impact if exploited (privilege escalation)Affects multiple Windows versions in common use
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDIf RD Gateway Service is not required, disable it on affected systems
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the September 2026 Microsoft security update (Windows 10 v1809: Build 10.0.17763.9245, Windows 10 v1607: Build 10.0.14393.9512, Windows Server 2016: Build 10.0.14393.9512, Windows Server 2019: Build 10.0.17763.9245, Windows Server 2022: Build 10.0.20348.5622, Windows Server 2025: Build 10.0.26100.33438)
Long-term hardening
0/1HARDENINGRestrict local account creation and monitor for unauthorized local user accounts with elevated privileges
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c5202c12-08da-48b5-bc27-0f63b18b595fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.