Skip to content

CVE-2026-69525

Windows Remote Desktop Services use-after-free allows unauthenticated remote code execution (CVE-2026-69525)

Critical 9.8 Vendor: Microsoft Published

Windows Remote Desktop Services use-after-free (CVE-2026-69525) allows unauthorised remote code execution over the network. CVSS 9.8 Critical; Microsoft rates it Important. No exploitation or public disclosure is recorded. Apply the September 2026 security update.

What happened

The vulnerability is a use-after-free (CWE-416) in Windows Remote Desktop Services. An attacker who can reach the service over a network can trigger the flaw to execute code on the affected host. The CVSS v3.1 score is 9.8 Critical: the attack is network-based, has low complexity, requires no privileges and no user interaction, and can have high impact on confidentiality, integrity and availability. Microsoft rates the issue Important.

Microsoft has not published a workaround. No exploitation has been reported, the vulnerability has not been publicly disclosed, and it is not listed in the CISA Known Exploited Vulnerabilities catalogue.

Who is affected

The CVE record names these affected releases: Windows 10 Version 1607 before 10.0.14393.9512; Windows 10 Version 1809 before 10.0.17763.9245; Windows 10 Version 21H2 before 10.0.19044.7725; Windows 10 Version 22H2 before 10.0.19045.7725; Windows 11 version 23H2 before 10.0.22631.7582; Windows 11 Version 24H2 before 10.0.26100.9445; Windows 11 Version 25H2 before 10.0.26200.9445; Windows 11 version 26H1 before 10.0.28000.2954; Windows Server 2012 and Windows Server 2012 (Server Core installation) before 6.2.9200.26349; and Windows Server 2012 R2 before 6.3.9600.23398. The fixed-version list on this page also includes builds for Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025.

What to do now

  1. Apply the Microsoft security update from the 2026-Sep bundle. Fixed builds include: Windows 10 1607 10.0.14393.9512 (KB5123099); Windows 10 1809 10.0.17763.9245 (KB5122876); Windows 10 21H2/22H2 10.0.19044.7725 / 10.0.19045.7725 (KB5122878); Windows 11 23H2 10.0.22631.7582 (KB5122880); Windows 11 24H2/25H2 10.0.26100.9445 / 10.0.26200.9445 (KB5124008); Windows 11 26H1 10.0.28000.2954 (KB5124012); Windows Server 2012 and Core 6.2.9200.26349 (KB5123065); Windows Server 2012 R2 and Core 6.3.9600.23398 (KB5123066); Windows Server 2016 and Core 10.0.14393.9512 (KB5123099); Windows Server 2019 and Core 10.0.17763.9245 (KB5122876); Windows Server 2022 10.0.20348.5622 (KB5122882); Windows Server 2025 and Core 10.0.26100.33438 (KB5122871).
  2. Prioritise hosts where Remote Desktop Services is reachable from untrusted networks.
  3. Where the service does not need to be internet-facing, restrict access with firewalls, VPN or network segmentation.
  4. Microsoft has not published a workaround, so if you cannot patch immediately, isolate unpatched hosts from network exposure and monitor sign-in activity.

How to detect it

Microsoft's advisory does not state specific indicators of compromise for this CVE. As a practical check, identify any Remote Desktop Services host reachable from the internet or guest networks and review sign-in events for unexpected accounts, repeated failed attempts, or successful connections from unfamiliar sources. Treat unpatched hosts with network exposure as urgent.

Beyond the patch

This is a reminder that unauthenticated network-facing services should be found before an advisory names them. Virtual CISO Services (vCISO) helps map exposed Remote Desktop Services and other open management ports, and Managed Detection & Response (MDR) provides EDR and SIEM visibility to spot code execution or credential abuse after a service is reached. Patch first, then confirm your exposure picture.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H210.0.19044.0 – < 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H210.0.19045.0 – < 10.0.19045.772510.0.19045.7725
Windows 11 version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H210.0.26100.0 – < 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H210.0.26200.0 – < 10.0.26200.944510.0.26200.9445
Windows 11 version 26H110.0.28000.0 – < 10.0.28000.295410.0.28000.2954
Windows Server 20126.2.9200.0 – < 6.2.9200.263496.2.9200.26349
(Server Core installation) 6.2.9200.26349
R2 6.3.9600.23398
R2 (Server Core installation) 6.3.9600.23398
Windows Server 2012 (Server Core installation)6.2.9200.0 – < 6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – < 6.3.9600.233986.3.9600.23398
(Server Core installation) 6.3.9600.23398

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.