Junglewise Threat Intelligence

CVE-2026-69287: Microsoft Windows Remote Desktop Services use-after-free privilege escalation

CVE-2026-69287 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Remote Desktop Services, a built-in component that allows remote management of Windows systems, contains a use-after-free vulnerability. An authorized local user can exploit this flaw to elevate their privileges on the system, potentially gaining administrative access and full control over the affected machine.

Technical details

A use-after-free vulnerability exists in Windows Remote Desktop Services, where memory is accessed after it has been freed, leading to memory corruption. The vulnerability requires an authenticated local attacker with user-level privileges to trigger the flaw. Successful exploitation allows privilege escalation to a higher privilege level, such as SYSTEM. Microsoft has addressed this issue with a security update.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats