Windows Remote Desktop Services Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-69475Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Untrusted pointer dereference vulnerability in Windows Remote Desktop Services allows an authorized local attacker to elevate privileges. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. Microsoft has released security updates for all affected versions.

What this means
What could happen
A logged-in user or service account on a Windows system running Remote Desktop Services could escalate their privileges to system level, allowing them to modify configurations, access sensitive data, or disrupt operations on that machine and potentially connected devices.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should prioritize this, especially if those systems are used as terminal servers, remote access gateways, or workstations with Remote Desktop Services enabled. Affects all system architectures (32-bit, x64, ARM64).
How it could be exploited
An attacker with a user account on the system (or through compromised credentials) could trigger the untrusted pointer dereference in Remote Desktop Services to execute code with elevated privileges, bypassing normal access controls.
Prerequisites
  • User or service account credentials on the target Windows system
  • Access to run code locally or remote desktop session to the affected system
  • Windows Remote Desktop Services must be running
Low complexityRequires valid user credentialsLocal exploitation only (not remotely exploitable without separate access)Affects server systems commonly used in utility environments
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply the September 2026 security update from Microsoft for your Windows version: Windows Server 2019 (Build 10.0.17763.9245), Windows Server 2022 (Build 10.0.20348.5622), Windows Server 2025 (Build 10.0.26100.33438), Windows 10 (version-specific builds listed in advisory), or Windows 11 (version-specific builds listed in advisory)
API: /api/v1/advisories/e2066dc9-40a2-433d-9b07-e6bf63776ce9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.