Critical SEVERITY — Vulnerability

CVE-2026-21533 — Microsoft Windows Improper Privilege Management Vulnerability

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

Platform
Windows Server
CVE Record
CVE-2026-21533
Advisory
CISA-KEV
Published
10 February 2026
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Status

This vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog as confirmed to be actively exploited. Not a theoretical risk — it is being used in the wild.

Description

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

Details

  • Vendor: Microsoft
  • Product: Windows
  • Date added to catalog: 2026-02-10

Actions mandated by CISA

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

  • Deadline for federal agencies: 2026-03-03
Microsoft Windows

Windows Server — Related Advisories

VIEW ALL →