← back
CVE-2026-21533

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 3.8%● KEVCWE-269
In short

A flaw in Windows Remote Desktop allows someone who already has access to the system to gain higher-level privileges and take control of more sensitive functions. This is dangerous because it lets attackers do more damage once they're already inside.

Technical detail

Improper privilege management in Windows Remote Desktop Services enables authenticated local attackers to escalate privileges through insufficient access controls. The vulnerability requires prior system access but allows unauthorized elevation to administrative or system-level context, potentially compromising system integrity and confidentiality.

Summary generated and translated by AI from the official description.
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →