CVE-2026-21533

9.5 CISA KEV

Microsoft · Windows Remote Desktop

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate their privileges locally on the affected system.

Executive summary

Windows Remote Desktop contains a high-severity privilege escalation vulnerability that is currently being exploited in the wild, allowing users to gain elevated system rights.

Vulnerability

This vulnerability involves improper management of privileges within the Windows Remote Desktop component. An authorized attacker with local access to the system can exploit this flaw to elevate their permissions, potentially gaining full administrative control.

Business impact

The ability to escalate privileges is a critical step in the "kill chain" for many attackers. With a CVSS score of 7.8 and confirmed active exploitation, this flaw allows low-privileged users to compromise the entire host. This can lead to unauthorized software installation, data theft, and the disabling of security controls.

Remediation

Immediate Action: Apply the latest Windows security updates immediately to address the privilege management flaw, as confirmed exploitation is occurring.

Proactive Monitoring: Review Windows Security logs for anomalous privilege escalation events or unauthorized use of administrative tools by standard users.

Compensating Controls: Enforce the principle of least privilege and restrict Remote Desktop Protocol (RDP) access to only those users who strictly require it for their job functions.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Immediate patching is required. Because this vulnerability is being used by threat actors to escalate privileges, failing to update systems leaves the environment vulnerable to persistent threats that can bypass standard user-level restrictions.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Fix documented version 10.0.14393.8868 per CVE record