CVE-2026-21533
HIGH KEVWindows 10/11 Remote Desktop Authenticated Privilege Escalation
Title source: llmExploitation Summary
CVE-2026-21533 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 10, 2026. EIP tracks 7 public exploits from researchers including XiaomingX, jenniferreire26, elvin31thai.
AI-analyzed exploit summary The repository claims to be a PoC for CVE-2026-21533 but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README contains vague marketing language and no technical details about the vulnerability.
Description
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Exploits (7)
The repository claims to be a PoC for CVE-2026-21533 but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README contains vague marketing language and no technical details about the vulnerability.
The repository provides a detailed writeup for CVE-2026-21533, a local privilege escalation vulnerability in Microsoft's Windows Remote Desktop service. It includes severity details, impact analysis, and usage instructions for a PoC exploit, but no actual exploit code is present in the provided files.
This repository contains a README describing CVE-2026-21533, a local privilege escalation vulnerability in Microsoft's Windows Remote Desktop service. No exploit code is provided, only a description of the vulnerability and its potential impact.
This repository contains a Python-based scanner for CVE-2026-21533, a Windows Remote Desktop Services local privilege escalation vulnerability. It checks for the presence of a security patch and tests registry permissions to detect potential vulnerability without exploiting it.
The repository claims to provide an exploit for CVE-2026-21533, a local privilege escalation vulnerability in Windows Remote Desktop, but contains no actual exploit code. Instead, it directs users to download the exploit from an external link (tinyurl.com), which is a common tactic for distributing malware or fake exploits.
The repository claims to provide an exploit for CVE-2026-21533 but lacks actual exploit code, instead redirecting users to an external download link. The README contains vague details and no technical analysis.
This script checks for the presence of a patch (KB5048614) and tests registry write permissions to determine if a system is vulnerable to CVE-2026-21533, a potential local privilege escalation (LPE) via RDP service registry manipulation.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H