CVE-2026-21533

HIGH KEV

Windows 10/11 Remote Desktop Authenticated Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-21533 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 10, 2026. EIP tracks 7 public exploits from researchers including XiaomingX, jenniferreire26, elvin31thai.

AI-analyzed exploit summary The repository claims to be a PoC for CVE-2026-21533 but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README contains vague marketing language and no technical details about the vulnerability.

Description

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Exploits (7)

github SUSPICIOUS 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-21533

The repository claims to be a PoC for CVE-2026-21533 but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README contains vague marketing language and no technical details about the vulnerability.

Classification
Suspicious 90%
Attack Type
Lpe
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Windows Remote Desktop service
Auth required
Prerequisites: local access to the system · low privileges
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WRITEUP 3 stars
by jenniferreire26 · poc
https://github.com/jenniferreire26/CVE-2026-21533

The repository provides a detailed writeup for CVE-2026-21533, a local privilege escalation vulnerability in Microsoft's Windows Remote Desktop service. It includes severity details, impact analysis, and usage instructions for a PoC exploit, but no actual exploit code is present in the provided files.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Windows Remote Desktop service
Auth required
Prerequisites: Local access to the system · Low-privileged user account
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 3 stars
by elvin31thai · poc
https://github.com/elvin31thai/CVE-2026-21533

This repository contains a README describing CVE-2026-21533, a local privilege escalation vulnerability in Microsoft's Windows Remote Desktop service. No exploit code is provided, only a description of the vulnerability and its potential impact.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Windows Remote Desktop service
Auth required
Prerequisites: Local access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER
by fevar54 · poc
https://github.com/fevar54/CVE-2026-21533_Scanner.py

This repository contains a Python-based scanner for CVE-2026-21533, a Windows Remote Desktop Services local privilege escalation vulnerability. It checks for the presence of a security patch and tests registry permissions to detect potential vulnerability without exploiting it.

Classification
Scanner 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows Remote Desktop Services (RDS)
Auth required
Prerequisites: Local access to the target system · Valid credentials
devstral-2 · analyzed Mar 10, 2026 Full analysis →
nomisec SUSPICIOUS
by richardpaimu34 · poc
https://github.com/richardpaimu34/CVE-2026-21533

The repository claims to provide an exploit for CVE-2026-21533, a local privilege escalation vulnerability in Windows Remote Desktop, but contains no actual exploit code. Instead, it directs users to download the exploit from an external link (tinyurl.com), which is a common tactic for distributing malware or fake exploits.

Classification
Suspicious 95%
Attack Type
Lpe
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Windows Remote Desktop (various versions)
Auth required
Prerequisites: Authorized access to the target system
devstral-2 · analyzed Feb 21, 2026 Full analysis →
nomisec SUSPICIOUS
by washingtonmaister · poc
https://github.com/washingtonmaister/CVE-2026-21533

The repository claims to provide an exploit for CVE-2026-21533 but lacks actual exploit code, instead redirecting users to an external download link. The README contains vague details and no technical analysis.

Classification
Suspicious 90%
Attack Type
Lpe
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Windows Remote Desktop (multiple versions)
Auth required
Prerequisites: Authorized access to the target system
devstral-2 · analyzed Feb 21, 2026 Full analysis →
nomisec SCANNER
by Pairs34 · poc
https://github.com/Pairs34/RDPVulnarableCheck

This script checks for the presence of a patch (KB5048614) and tests registry write permissions to determine if a system is vulnerable to CVE-2026-21533, a potential local privilege escalation (LPE) via RDP service registry manipulation.

Classification
Scanner 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows RDP Service (unpatched systems missing KB5048614)
Auth required
Prerequisites: Local access to a Windows system · Low-privileged user account
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.1911
EPSS Percentile 95.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-02-10
VulnCheck KEV 2026-02-10
ENISA EUVD EUVD-2026-7343
CWE
CWE-269
Status published
Products (36)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.8868
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8389
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.6937
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.6937
Microsoft/Windows 11 version 22H3 10.0.22631.0 - 10.0.22631.6649
Microsoft/Windows 11 Version 23H2 10.0.22631.0 - 10.0.22631.6649
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.7840
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.7840
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.1575
Microsoft/Windows 11 Version 26H1 10.0.28000.0 - 10.0.28000.1575
... and 26 more
Published Feb 10, 2026
KEV Added Feb 10, 2026
Tracked Since Feb 18, 2026