Windows Remote Desktop Service
by Microsoft
CVEs (38)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-61365 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61364 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61356 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53722 | Hig | 0.50 | 7.5 | 0.22 | Aug 12, 2025 | Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-69599 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69539 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69514 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | ||
| CVE-2025-48814 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2025 | Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-21330 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2024-49075 | Hig | 0.49 | 7.5 | 0.03 | Dec 12, 2024 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2020-16863 | Hig | 0.49 | 7.5 | 0.06 | Oct 16, 2020 | A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Desktop Service on the… | ||
| CVE-2026-69536 | Hig | 0.46 | 7.1 | 0.01 | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69287 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59202 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69616 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. | ||
| CVE-2024-43456 | Med | 0.31 | 4.8 | 0.01 | Oct 8, 2024 | Windows Remote Desktop Services Tampering Vulnerability | ||
| CVE-2026-58626 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-50369 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.50cvss 7.5epss 0.22
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.49cvss 7.5epss 0.02
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.06
A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Desktop Service on the…
- risk 0.46cvss 7.1epss 0.01
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.
- risk 0.31cvss 4.8epss 0.01
Windows Remote Desktop Services Tampering Vulnerability
- risk 0.00cvss 8.8epss 0.01
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- risk 0.00cvss 8.8epss 0.01
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Page 2 of 2