Executive brief
Windows Remote Desktop Services (RDS) is a core Windows component that allows users to connect to computers remotely over a network. A heap buffer overflow vulnerability allows an authenticated attacker with network access to execute arbitrary code with system privileges, potentially leading to complete compromise of affected systems.
Technical details
A heap-based buffer overflow exists in Windows Remote Desktop Services that can be exploited by an authorized attacker over the network. The vulnerability allows an authenticated remote attacker to trigger a heap memory corruption condition, leading to code execution in the context of the RDS service. The attack requires an attacker to have valid credentials and network connectivity to an RDS endpoint. Successful exploitation results in arbitrary code execution with the privileges of the RDS service, typically SYSTEM-level access. Patches are available from Microsoft.
Affected products
- Microsoft Windows Remote Desktop Services
Timeline
- 2026-09-08: disclosed