Executive brief
A security vulnerability has been identified in Windows Remote Desktop Services, a component that allows users to access their computers or servers remotely. An attacker who already has basic user access to the network could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the affected system, potentially leading to data theft or further disruption of business operations.
Technical details
This vulnerability is classified as a use-after-free (CWE-416) and a race condition (CWE-362) within Windows Remote Desktop Services. An attacker with low-privileged network access can exploit improper synchronization during concurrent execution to trigger a memory corruption state. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining full system control. The attack vector is network-based and does not require user interaction, though it does require initial authentication (PR:L). Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
- 2026-07-14: patched: Security updates made available by Microsoft.