EIP-2026-103811

PRE-CVE

RDPGuard 9.9.9 - Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103811. PoCs published by Ahmet Ümit BAYRAM.

AI-analyzed exploit summary This exploit leverages a privilege escalation vulnerability in RDPGuard 9.9.9 by allowing an attacker to execute a malicious .bat file as NT AUTHORITY\SYSTEM through the 'Custom Actions / Notifications' feature. The exploit requires user interaction to trigger the payload via a 'Test Run' button.

Description

RDPGuard 9.9.9 - Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by Ahmet Ümit BAYRAM · textlocalmultiple
https://www.exploit-db.com/exploits/52289

This exploit leverages a privilege escalation vulnerability in RDPGuard 9.9.9 by allowing an attacker to execute a malicious .bat file as NT AUTHORITY\SYSTEM through the 'Custom Actions / Notifications' feature. The exploit requires user interaction to trigger the payload via a 'Test Run' button.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: RDPGuard 9.9.9
Auth required
Prerequisites: Access to RDPGuard GUI · Ability to create/modify a .bat file · Listener set up for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026