Description
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Windows Remote Desktop Services that permits an attacker who has already authenticated to the target system to execute arbitrary code on the machine. The flaw lies in the handling of RDP packets that free memory before any further checks, allowing the attacker to manipulate the freed pointer. The primary impact is remote code execution, giving the attacker full control over the operating system, potentially leading to data theft, privilege escalation, and system compromise.

Affected Systems

Affected systems are Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025, including the Server Core installation. The platforms impacted include x64 and arm64 architectures, as shown by the common platform enumeration strings. All these releases provide Remote Desktop Services and have not yet received the official Microsoft patch listed in the update guide.

Risk and Exploitability

The CVSS score of 7.5 classifies the flaw as high severity, and the lack of an EPSS value means there is no publicly available data on exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, but the typical remote attack vector exploits the RDP interface over the network, requiring the attacker to be authenticated or have valid credentials to the target machine. If exploited, the attacker could execute arbitrary code, compromise confidentiality, integrity, and availability of the system, and potentially use the machine as a pivot point for further attacks.

Generated by OpenCVE AI on September 8, 2026 at 22:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Windows update that includes the fix for CVE‑2026‑69599 from Microsoft’s update guide.
  • If an immediate patch is unavailable, disable Remote Desktop Services on the affected machines until the patch can be applied.
  • Enable logging for Remote Desktop Services and monitor the logs for suspicious authentication attempts or anomalous RDP traffic; isolate any compromised systems promptly.

Generated by OpenCVE AI on September 8, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Title Remote Desktop Services Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:44.228Z

Reserved: 2026-08-03T21:18:49.124Z

Link: CVE-2026-69599

cve-icon Vulnrichment

Updated: 2026-09-09T09:57:13.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:30.537

Modified: 2026-09-14T19:30:13.687

Link: CVE-2026-69599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:59:25Z

Weaknesses