Remote Desktop Services Remote Code Execution Vulnerability

Plan PatchCVSS 7.1CVE-2026-69536Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary

A use-after-free vulnerability in Windows Remote Desktop Services allows an authorized attacker to execute code remotely over the network. The vulnerability affects multiple versions of Windows Server 2025 and Windows 11 (versions 23H2, 24H2, and 26H1) on both x64 and ARM64 architectures.

What this means
What could happen
An authenticated attacker with remote access to Remote Desktop Services could execute arbitrary code on the affected system, potentially compromising process control systems, data integrity, or availability of the server.
Who's at risk
System administrators and operators managing Windows Server 2025 and Windows 11 workstations (versions 23H2, 24H2, 26H1 on x64 or ARM64 systems) should prioritize this patch, especially if these systems provide remote access for operational or engineering purposes.
How it could be exploited
An attacker must establish an authenticated Remote Desktop connection to the target system over the network, then trigger the use-after-free condition to execute arbitrary code with the privileges of the RDS service.
Prerequisites
  • Valid credentials to access Remote Desktop Services
  • Network connectivity to the RDS port (typically 3389)
  • Ability to establish an authenticated RDS session
  • User interaction may be required to trigger the vulnerability
remotely exploitablerequires authenticationhigh impact on confidentiality and integrity
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict Remote Desktop Services network access to authorized engineering workstations and administrative networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's September 2026 security update to all affected Windows systems
Long-term hardening
0/1
HARDENINGEnforce strong authentication for Remote Desktop Services, including multi-factor authentication where possible
API: /api/v1/advisories/fda8aebe-bf8f-4b9a-8423-508c1a99b889

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.