Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2024-49132
Key Information:
- Vendor
- Microsoft
- Status
- Windows 10 Version 1809
- Windows Server 2019
- Windows Server 2019 (server Core Installation)
- Windows Server 2022
- Vendor
- CVE Published:
- 12 December 2024
Summary
A vulnerability exists in Microsoft Windows Remote Desktop Services that allows an attacker to execute arbitrary code on an affected system. Successful exploitation of this vulnerability can enable attackers to take control of the system, potentially accessing sensitive information or implementing malicious software. This vulnerability affects multiple versions of Windows server and client operating systems. It is crucial for users and administrators to apply the latest security updates and implement necessary mitigations.
Affected Version(s)
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6659
Windows 10 Version 21H2 32-bit Systems 10.0.19043.0 < 10.0.19044.5247
Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.5247
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved