Windows Remote Desktop Services Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-69475Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Untrusted pointer dereference vulnerability in Windows Remote Desktop Services allows an authorized local attacker to elevate privileges. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. Microsoft has released security updates for all affected versions.
What this means
What could happen
A logged-in user or service account on a Windows system running Remote Desktop Services could escalate their privileges to system level, allowing them to modify configurations, access sensitive data, or disrupt operations on that machine and potentially connected devices.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should prioritize this, especially if those systems are used as terminal servers, remote access gateways, or workstations with Remote Desktop Services enabled. Affects all system architectures (32-bit, x64, ARM64).
How it could be exploited
An attacker with a user account on the system (or through compromised credentials) could trigger the untrusted pointer dereference in Remote Desktop Services to execute code with elevated privileges, bypassing normal access controls.
Prerequisites
- User or service account credentials on the target Windows system
- Access to run code locally or remote desktop session to the affected system
- Windows Remote Desktop Services must be running
Low complexityRequires valid user credentialsLocal exploitation only (not remotely exploitable without separate access)Affects server systems commonly used in utility environments
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the September 2026 security update from Microsoft for your Windows version: Windows Server 2019 (Build 10.0.17763.9245), Windows Server 2022 (Build 10.0.20348.5622), Windows Server 2025 (Build 10.0.26100.33438), Windows 10 (version-specific builds listed in advisory), or Windows 11 (version-specific builds listed in advisory)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e2066dc9-40a2-433d-9b07-e6bf63776ce9Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.