Executive brief
Windows Remote Desktop Services contains a use-after-free vulnerability that allows an authorized network attacker to execute arbitrary code with system privileges. Remote Desktop Services is a core Windows component that enables users to connect to and control computers remotely. A successful exploit could give an attacker complete control over affected systems, compromising data and operations.
Technical details
A use-after-free vulnerability exists in Windows Remote Desktop Services where freed memory is accessed after deallocation, potentially allowing arbitrary code execution. The vulnerability requires an authenticated attacker with network access to the RDP service. An attacker can leverage this flaw to achieve remote code execution with the privileges of the affected service. Microsoft has issued security updates to remediate this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- patched: Microsoft security update available