Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2024-49129

7.5HIGH

Key Information:

Vendor
Microsoft
Status
Windows Server 2019
Windows Server 2019 (server Core Installation)
Windows Server 2022
Windows Server 2025 (server Core Installation)
Vendor
CVE Published:
12 December 2024

Summary

The Windows Remote Desktop Gateway (RD Gateway) is impacted by a denial of service vulnerability that could allow an attacker to disrupt the availability of the service. This vulnerability may cause significant interruptions for users attempting to access remote resources, potentially leading to operational challenges within organizations. It is essential to assess the implications of this vulnerability on your network and ensure appropriate measures are taken to mitigate the risks.

Affected Version(s)

Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.25222

Windows Server 2012 R2 (Server Core installation) x64-based Systems 6.3.9600.0 < 6.3.9600.22318

Windows Server 2012 R2 x64-based Systems 6.3.9600.0 < 6.3.9600.22318

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.