Windows Remote Desktop Services privilege escalation vulnerability affecting multiple Windows versions. Allows authorized attackers to elevate privileges locally, potentially leading to full system compromise on RDP-enabled systems. Listed in CISA KEV indicating active exploitation.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-02-10
Added to CISA KEV: 2026-02-10 0 DAY BETWEEN CVE AND KEV
CVE-2026-21533 is a security vulnerability involving improper privilege management within Windows Remote Desktop Services (RDS)?id=CVE-2026-21533?kagi_q=CVE-2026-21533. It was disclosed and patched by Microsoft in February 2026 [6].
OpenCVE Recommended Actions Apply the Microsoft security update released for CVEโ2026โ21533 as detailed on the MSRC update guide. If patching cannot be performed immediately, restrict Remote Desktop access to trusted networks, consider network segmentation or placing RDP behind a gateway to reduce eโฆ
CVE-2026-21533 is a worrying reminder that even after decades, privilege management bugs still surface in complex protocols like Remote Desktop. If a local user can become SYSTEM with minimal effort, it makes ransomware and internal attacks much easier.
CVE-2026-21533 is a post-initial-access privilege escalation technique. It fits into common attack chains involving RDP exposure. MITRE ATT&CK ...
Description. Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Metrics. CVSS Version 4.0 ... This is a potential security issue, you are being redirected to https://nvd.nist.govโฆ
Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers ...
The CVE-2026-21533 exploit binary modifies a service configuration key, replacing it with an attacker-controlled key, which could enable ...
CVE-2026-21533 is a zero-day vulnerability with a CVSS score of 7.8. Exploitation of this flaw allows attackers to escalate privileges without ...