Remote Desktop Gateway Service Elevation of Privilege Vulnerability
Plan PatchCVSS 7.1CVE-2026-69338Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
Use after free vulnerability in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. Affects Windows 10 (versions 1607, 1809) and Windows Server (2016, 2019, 2022, 2025).
What this means
What could happen
An attacker with valid credentials on your network could exploit this to gain higher-level access on a Windows Server or workstation running Remote Desktop Gateway, potentially allowing them to access sensitive systems or bypass network access controls.
Who's at risk
IT and security teams managing Windows Server (2016, 2019, 2022, 2025) or Windows 10 workstations (versions 1607, 1809) that use Remote Desktop Gateway for remote access. This primarily affects network administrators, organizations with hybrid or remote work infrastructure, and facilities managing remote connections to operational systems.
How it could be exploited
An attacker with valid network credentials connects to a system running Remote Desktop Gateway Service, triggers a use-after-free condition in the service, and exploits it to run code with elevated privileges. User interaction (such as a specific action on the attacker's part or configuration) is required to trigger the vulnerability.
Prerequisites
- User interaction or specific configuration required to trigger the vulnerability
Affects multiple Windows Server and workstation versions
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
Exploitation assessment: Exploitation Less Likely. Apply the 2026-Sep security update.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b8a4af9e-f32e-4b2a-83ad-4c6efbef6a31Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.