Remote Desktop Licensing Service Remote Code Execution Vulnerability
Key Information
- Vendor
- Microsoft
- Status
- Windows Server 2019
- Windows Server 2019 (server Core Installation)
- Windows Server 2022
- Windows Server 2022, 23h2 Edition (server Core Installation)
- Vendor
- CVE Published:
- 9 July 2024
Badges
Summary
The CVE-2024-38077 vulnerability is a critical remote code execution (RCE) flaw in the Windows Remote Desktop Licensing Service. Also known as "MadLicense," this pre-authentication vulnerability allows attackers to execute arbitrary code on vulnerable systems without requiring user interaction. This poses a significant threat as it impacts Windows Server versions from 2000 to the latest 2025 preview. The vulnerability has the potential to affect over 170,000 Remote Desktop Licensing Services exposed to the public internet. The PoC exploit released by researchers demonstrates how this vulnerability can be leveraged to achieve full remote code execution capabilities, and there are no known exploits circulating for this vulnerability, despite its potential for widespread attacks. Microsoft has released a patch to address the vulnerability, and organizations are urged to apply this update to mitigate risks.
Affected Version(s)
Windows Server 2019 < 10.0.17763.6054
Windows Server 2019 (Server Core installation) < 10.0.17763.6054
Windows Server 2022 < 10.0.20348.2582
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
LPE FTW β PSW #839
This week: Option ROMS are a novel way to compromise a system at the lowest level, Sinkclose opens AMD processors up to attacks, at home in your firmware exploiting SMM complete with examples, Sonos speakers get hacked and enable attackers to listen in on your conversations, DEF CON badges use new ...
3 months ago
PoC Released for 0-click RCE Flaw Impacting Windows Server - MadLicense
The vulnerability, dubbed "MadLicense," is a pre-authentication RCE flaw that allows attackers to execute arbitrary code on vulnerable systems without requiring user interaction.
3 months ago
CVSS V3.1
Timeline
- πΎ
Exploit exists.
- π₯
Vulnerability reached the number 1 worldwide trending spot.
Vulnerability started trending.
First article discovered by CybersecurityNews
Vulnerability published.