Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-69627Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in the Windows Remote Desktop Licensing Service allows an authorized local user to disclose sensitive information from the service process memory. The vulnerability requires local user account access and does not allow remote exploitation or system modification. All versions of Windows 10, Windows 11, and Windows Server 2016 through 2025 are affected across all architectures and installation types.
What this means
What could happen
An authorized local user could read sensitive information from the Windows Remote Desktop Licensing Service memory, potentially exposing configuration data or other system secrets.
Who's at risk
Windows IT administrators managing Windows 10 and Windows 11 desktops or Windows Server 2016, 2019, 2022, and 2025 systems. This affects all hardware architectures (32-bit, x64, ARM64) and includes both full and Server Core installations.
How it could be exploited
An attacker with a local user account on the Windows machine could trigger an out-of-bounds read in the Remote Desktop Licensing Service process memory to extract sensitive information without modifying or crashing the system.
Prerequisites
- Local user account access to the Windows system
- Ability to interact with the Remote Desktop Licensing Service
Requires local user authenticationLow exploit probability (0.4% EPSS)Information disclosure only—no remote execution or system compromise
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Windows security updates for your Windows version (September 2026 or later)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5fb14587-e19f-4e98-976d-c8c51d193255Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.