Executive brief
Windows Remote Desktop Services contains a pointer dereference vulnerability that allows an authenticated local user to escalate privileges on an affected system. An attacker who gains initial access to a system with RDP enabled could exploit this flaw to obtain elevated permissions, enabling further malicious activity such as installing backdoors, stealing sensitive data, or compromising system integrity.
Technical details
The vulnerability is a pointer dereference flaw in Windows Remote Desktop Services that enables privilege escalation. The flaw requires an authenticated local attacker with at least user-level access to the system. By leveraging untrusted pointer operations within RDS, an attacker can execute code in the context of a higher-privileged process, achieving local privilege escalation. The vulnerability has a CVSS score of 7.8 (high severity) and does not require network access, though it does require prior system authentication.
Affected products
- Microsoft Windows Remote Desktop Services
Timeline
- 2026-09-08: disclosed