Missing Authentication for Critical Function in Microsoft Windows and Windows Server - CVE-2026-61367
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to missing authentication for critical function in Windows Remote Desktop Services when invoking a critical function locally. A local user can access the vulnerable function without proper authentication to elevate privileges.
Successful exploitation could allow the attacker to gain SYSTEM privileges.
Affected software
Windows Server
How to mitigate CVE-2026-61367
Windows Server - addressed in versions 2012 R2 6.3.9600.23337, 2012 6.2.9200.26279, 2016 10.0.14393.9418, 2019 10.0.17763.9115, 2022 10.0.20348.5440, 2022 10.0.20348.5499, 2025 10.0.26100.33222, 2025 10.0.26100.33296