Executive brief
A security vulnerability has been identified in Microsoft Windows Remote Desktop Services, a component used to access computers and servers remotely. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This vulnerability is reportedly being used in active attacks, making it a high priority for remediation to prevent unauthorized system takeovers.
Technical details
A local privilege escalation vulnerability (CWE-269) exists in Microsoft Windows Remote Desktop Services due to improper privilege management. An attacker with low-privileged local access can exploit this flaw to gain SYSTEM-level privileges on the affected host. The attack vector is local and requires no user interaction, though the attacker must already have an authenticated foothold on the system. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.
Affected products
- Microsoft Windows Windows 10, Windows 11, Windows Server 2012, 2016, 2019, 2022, 2025
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory
- 2026-02-10: kev added: Added to CISA KEV catalog due to active exploitation.
- 2026-02-10: exploited