Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-61356

CVE-2026-61356: Windows 10 1809 Privilege Escalation Flaw

CVE-2026-61356 is a privilege escalation vulnerability in Windows 10 1809 Remote Desktop Services that lets authorized attackers gain elevated privileges. This article covers technical details, affected systems, and mitigation.

Published:

CVE-2026-61356 Overview

CVE-2026-61356 is a local privilege escalation vulnerability in Windows Remote Desktop Services caused by missing authentication for a critical function [CWE-306]. An authorized attacker with low privileges on an affected system can elevate to higher privileges without additional authentication. Microsoft assigned this issue a CVSS 3.1 score of 7.8 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The flaw affects a broad range of Windows client and server platforms, including Windows 10, Windows 11, and Windows Server 2019 through 2025. Exploitation requires local access, but successful abuse yields full confidentiality, integrity, and availability impact on the target host.

Critical Impact

A local, authenticated attacker can escalate privileges on Windows systems running Remote Desktop Services, achieving high impact on confidentiality, integrity, and availability.

Affected Products

  • Microsoft Windows 10 (1809, 21H2, 22H2) on x86, x64, and ARM64
  • Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1) on x64 and ARM64
  • Microsoft Windows Server 2019, Windows Server 2022, and Windows Server 2025

Discovery Timeline

  • 2026-08-11 - CVE-2026-61356 published to NVD
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-61356

Vulnerability Analysis

CVE-2026-61356 exists in Windows Remote Desktop Services (RDS), the component that hosts remote session functionality and related management interfaces. The affected code path exposes a privileged operation without verifying that the caller is authorized to invoke it. As categorized by CWE-306: Missing Authentication for Critical Function, the design assumes an authenticated context but skips an explicit authorization check before performing a sensitive action.

The result is that any interactive or session-based user on the machine can trigger the operation and obtain elevated rights. Because the vulnerability sits inside a system service, successful exploitation typically yields SYSTEM-equivalent access, enabling credential theft, tampering with security products, and persistent access.

Root Cause

The root cause is an absent authorization check on a critical Remote Desktop Services function. The service accepts the request based on the ambient session context rather than validating the caller's privilege level. Refer to the Microsoft CVE-2026-61356 Advisory for vendor-specific technical detail.

Attack Vector

The attack vector is local. An attacker must already have valid credentials on the target Windows host, such as a standard user account or an active RDP session. From that context, the attacker calls the vulnerable RDS interface directly to perform an action reserved for higher-privileged principals. No user interaction is required, and the exploit does not cross a scope boundary. Public proof-of-concept code, CISA KEV listing, and confirmed in-the-wild exploitation were not reported at the time of publication. The EPSS forecast on 2026-08-13 places likelihood of exploitation in the lower range.

No verified exploit code is publicly available. See the Microsoft CVE-2026-61356 Advisory for authoritative details.

Detection Methods for CVE-2026-61356

Indicators of Compromise

  • Unexpected process creations by svchost.exe hosting Remote Desktop Services (TermService, SessionEnv, UmRdpService) spawning cmd.exe, powershell.exe, or LOLBins.
  • New local or domain accounts added shortly after RDP session activity from low-privileged users.
  • Modifications to security-sensitive registry keys or service configurations following interactive logons.

Detection Strategies

  • Correlate Windows Security event IDs 4624 (logon), 4672 (special privileges assigned), and 4688 (process creation) to spot low-privileged sessions gaining SYSTEM-level tokens.
  • Alert on child processes of Remote Desktop Services host processes that do not match a known baseline.
  • Hunt for token manipulation and impersonation patterns originating from RDP session IDs.

Monitoring Recommendations

  • Ingest Windows Sysmon, Security, and Terminal Services operational logs into a centralized analytics platform for cross-host correlation.
  • Track patch state across Windows 10, Windows 11, and Windows Server fleets to identify systems still exposed to CVE-2026-61356.
  • Monitor RDS-enabled hosts for anomalous local privilege changes and abnormal service restarts.

How to Mitigate CVE-2026-61356

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft CVE-2026-61356 Advisory to all affected Windows 10, Windows 11, and Windows Server systems.
  • Prioritize patching on multi-user systems, jump hosts, and Remote Desktop Session Hosts where multiple users share the machine.
  • Audit local user accounts and remove unnecessary interactive logon rights on RDS-enabled systems.

Patch Information

Microsoft released fixes through its standard Update Guide. Refer to the Microsoft CVE-2026-61356 Advisory for the exact KB articles corresponding to each Windows version and architecture listed under Affected Products.

Workarounds

  • Disable Remote Desktop Services on hosts that do not require it by setting the TermService startup type to Disabled.
  • Restrict Remote Desktop access to trusted administrative users through Group Policy and the Remote Desktop Users group.
  • Enforce Network Level Authentication (NLA) and require multi-factor authentication for all remote sessions to reduce the population of attackers who can reach the local attack surface.
bash
# Example: disable Remote Desktop Services where it is not required
sc.exe config TermService start= disabled
sc.exe stop TermService

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.