CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
— CISA
Windows Remote Desktop Services Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23022Patch KB5075970 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25923Patch KB5075971 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8868Patch KB5075999 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7840Fixed in 10.0.26100.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32370Fixed in 10.0.26100.32313Patch KB5075942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6649Patch KB5075941 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7840Fixed in 10.0.26200.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2149Patch KB5075897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4773Fixed in 10.0.20348.4711Patch KB5075943 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8389Patch KB5075904 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1575Patch KB5077179
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21533?
CVE-2026-21533 is considered a high severity vulnerability due to its potential for allowing privilege escalation.
How do I fix CVE-2026-21533?
To fix CVE-2026-21533, you should apply the latest security updates provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2026-21533?
CVE-2026-21533 affects various versions of Windows including Windows 10, Windows 11, and Windows Server editions.
Can CVE-2026-21533 be exploited remotely?
CVE-2026-21533 requires local access, as it is an elevation of privilege vulnerability that cannot be exploited remotely.
What are the potential impacts of CVE-2026-21533 if exploited?
Exploitation of CVE-2026-21533 could allow an attacker to gain elevated privileges, resulting in unauthorized access to sensitive data or system functions.