Remote Desktop Services Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-69599Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows Remote Desktop Services allows an authorized attacker with valid RDP credentials to execute arbitrary code over the network. The vulnerability affects Windows Server 2025 and Windows 11 (versions 23H2, 24H2, 25H2, and 26H1) on both x64 and ARM64 architectures. Exploitation requires valid Remote Desktop credentials and network access to the RDP service.

What this means
What could happen
An attacker with valid credentials could run arbitrary code on a Windows server or workstation through Remote Desktop Services, potentially disrupting operations or compromising system integrity.
Who's at risk
Organizations running Windows Server 2025 or Windows 11 systems (versions 23H2, 24H2, 25H2, or 26H1) that use Remote Desktop Services for administrative access or server management should prioritize patching. This affects any facility using RDP-enabled workstations or servers for remote management, including water authorities and utilities managing SCADA systems through Windows jump hosts.
How it could be exploited
An attacker with valid Remote Desktop credentials connects to a vulnerable Windows Server or Windows 11 system over the network, triggers a use-after-free condition in the Remote Desktop Services process, and executes arbitrary code with the privileges of the RDS service.
Prerequisites
  • Valid Remote Desktop Protocol (RDP) credentials
  • Network access to RDP port 3389 (or custom RDP port if configured)
  • Target system must have Remote Desktop Services enabled
remotely exploitablerequires valid credentialsaffects server and workstation operating systemsmoderate complexity attack
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict network access to RDP port 3389 using firewall rules to only authorized administrative workstations
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply the September 2026 Microsoft security update to Windows Server 2025 (Build 10.0.26100.33438 or later)
All products
HOTFIXApply the September 2026 Microsoft security update to Windows 11 Version 23H2 (Build 10.0.22631.7582 or later)
HOTFIXApply the September 2026 Microsoft security update to Windows 11 Version 24H2 (Build 10.0.26100.9445 or later)
HOTFIXApply the September 2026 Microsoft security update to Windows 11 Version 25H2 (Build 10.0.26200.9445 or later)
HOTFIXApply the September 2026 Microsoft security update to Windows 11 Version 26H1 (Build 10.0.28000.2954 or later)
Long-term hardening
0/1
HARDENINGUse Multi-Factor Authentication (MFA) for all Remote Desktop access to reduce risk from credential compromise
API: /api/v1/advisories/d3e784a5-08f1-44a6-ad01-1268f9ed4db7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Services Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse