Junglewise Threat Intelligence

CVE-2026-56647: Microsoft Windows Remote Access Service privilege escalation

CVE-2026-56647 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 24H2, Microsoft Windows Server 2012 R2, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Remote Access Service, which is used to provide remote connectivity to corporate networks. An attacker with basic user access can exploit this flaw to gain higher-level administrative privileges across the network. This could allow an unauthorized individual to take full control of affected systems, potentially leading to data theft or significant operational disruption.

Technical details

This vulnerability is classified as an integer overflow or wraparound (CWE-190) within the Windows Remote Access Service (RAS) Infrastructure. An attacker with low-privileged credentials can exploit this flaw over the network without any user interaction. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining full system control. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23291

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats