Junglewise Threat Intelligence

CVE-2026-80096: Microsoft Windows Remote Desktop Services out-of-bounds read

CVE-2026-80096 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Windows Remote Desktop Services (RDS), a built-in system component that allows users to connect to and control computers remotely, contains an out-of-bounds read vulnerability. An authenticated attacker with network access could exploit this flaw to gain higher-level privileges on the affected system, potentially compromising security infrastructure and enabling lateral movement within an organization.

Technical details

An out-of-bounds read vulnerability exists in Windows Remote Desktop Services. The flaw allows an authenticated attacker with network connectivity to the RDS service to read memory beyond intended boundaries, leading to privilege escalation. The vulnerability is reachable over the network from a remote attacker who has valid credentials or access to the RDS endpoint. Successful exploitation enables an attacker to elevate their privileges and potentially gain system-level access. Patches are available from Microsoft.

Affected products

  • Microsoft Windows Remote Desktop Services

Timeline

  • 2026-09-08: disclosed

References

Related threats