Junglewise Threat Intelligence

CVE-2026-69536: Microsoft Windows Remote Desktop Services use-after-free

CVE-2026-69536 · Severity: high · CVSS 7.1 · Published 2026-09-08

Executive brief

Windows Remote Desktop Services (RDS) is a Microsoft service that enables remote access to Windows systems over a network. A use-after-free vulnerability in RDS allows an authorized network user to execute arbitrary code on the affected system, potentially compromising the entire remote session and any sensitive data or systems accessible from it.

Technical details

A use-after-free vulnerability exists in Windows Remote Desktop Services, where a freed memory region is accessed after deallocation. The vulnerability requires the attacker to be an authenticated RDS user with valid credentials, and network reachability to the RDS endpoint. An authorized attacker can exploit this flaw to achieve remote code execution (RCE) over the network, gaining the privileges of the RDS service or the logged-in user. Microsoft has released security updates to remediate this issue.

Affected products

  • Microsoft Windows Remote Desktop Services

Timeline

  • 2026-09-08: disclosed

References

Related threats