Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2024-49123

8.1HIGH

Key Information:

Vendor
Microsoft
Status
Windows 10 Version 1809
Windows Server 2019
Windows Server 2019 (server Core Installation)
Windows Server 2022
Vendor
CVE Published:
12 December 2024

Summary

The vulnerability in Windows Remote Desktop Services enables an attacker to execute arbitrary code on affected systems without user intervention. By leveraging this flaw, an unauthorized user can gain control over the target machine, potentially leading to data theft, further infiltration into corporate networks, and other malicious activities. Organizations utilizing these services need to prioritize the application of patches and implement necessary security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6659

Windows 10 Version 21H2 32-bit Systems 10.0.19043.0 < 10.0.19044.5247

Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.5247

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.