Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-58626

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Windows Remote Desktop Services Remote Code Execution Vulnerability

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability?

An authenticated attacker could exploit this vulnerability by connecting to a target system via Remote Desktop Protocol (RDP) and sending specially crafted requests that trigger a use-after-free condition in the Remote Desktop service, allowing the attacker to execute arbitrary code on the target system.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

An attacker must first have access to a Windows system as an authenticated user and then use that system to establish a connection to the target server and send the malicious data that triggers the vulnerability.

Обновления

ПродуктСтатьяОбновление
Windows Server 2022
Windows 10 Version 21H2 for 32-bit Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 22H2 for x64-based Systems
Windows 10 Version 22H2 for ARM64-based Systems
Windows 10 Version 22H2 for 32-bit Systems
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 24H2 for x64-based Systems
Windows Server 2025

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

EPSS

Процентиль: 54%
0.00851
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
16 дней назад

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVSS3: 8.8
github
16 дней назад

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

EPSS

Процентиль: 54%
0.00851
Низкий

8.8 High

CVSS3