Junglewise Threat Intelligence

CVE-2026-69539: Microsoft Windows Remote Desktop Services use-after-free

CVE-2026-69539 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Remote Desktop Services is a Windows feature that allows users to access computers remotely over a network. A use-after-free vulnerability in this service could allow an authorized attacker to execute arbitrary code on the target system, potentially compromising the entire computer and any sensitive data it contains.

Technical details

A use-after-free vulnerability exists in Windows Remote Desktop Services, where freed memory is accessed after deallocation, allowing memory corruption. An authorized attacker with network access to RDP can exploit this vulnerability to execute arbitrary code in the context of the affected service. The vulnerability requires an attacker to be authenticated to the RDP service. Patches are expected to be available through Microsoft's security update process.

Affected products

  • Microsoft Windows Remote Desktop Services <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats