Executive brief
Windows Remote Desktop Services (RDS) is a Microsoft system component that enables remote access to servers and desktops. A use-after-free vulnerability allows an unauthorized attacker to execute arbitrary code over the network without authentication, potentially compromising an entire system or organizational network.
Technical details
The vulnerability is a use-after-free flaw in Windows Remote Desktop Services, a memory safety issue where freed memory is accessed after deallocation, leading to arbitrary code execution. The vulnerability is reachable over the network without requiring prior authentication or user interaction. An attacker can exploit this remotely to gain code execution with the privileges of the RDS service, potentially enabling system compromise, lateral movement, or persistence mechanisms. Patches are available from Microsoft's security update guides.
Affected products
- Microsoft Windows Remote Desktop Services <UNKNOWN>
Timeline
- 2026-09-08: disclosed