Windows Remote Desktop Services Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition.
How could an attacker exploit this vulnerability? An attacker could successfully exploit this vulnerability by connecting to a system with the Remote Desktop Gateway role, triggering the race condition to create a use-after-free scenario, and then leveraging this to execute arbitrary code.
🎯 Affected products13
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
- Windows Server 2025
- Windows Server 2025 (Server Core installation)
✅ Remediation
KB5050008 (Security Update) — fixed build 10.0.17763.6775 KB5049983 (Security Update) — fixed build 10.0.20348.3091 KB5048800 (SecurityHotpatchUpdate) — fixed build 10.0.20348.2908 KB5050009 (Security Update) — fixed build 10.0.26100.2894 KB5048794 (SecurityHotpatchUpdate) — fixed build 10.0.26100.2528 KB5049984 (Security Update) — fixed build 10.0.25398.1369 KB5049993 (Security Update) — fixed build 10.0.14393.7699 KB5048699 (Monthly Rollup) — fixed build 6.2.9200.25222 KB5050048 (Monthly Rollup) — fixed build 6.3.9600.22371
🔗 References (19)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49120
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5050008
- referencehttps://support.microsoft.com/help/5050008
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5049983
- referencehttps://support.microsoft.com/help/5049983
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5048800
- referencehttps://support.microsoft.com/help/5048800
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5050009
- referencehttps://support.microsoft.com/help/5050009
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5048794
- referencehttps://support.microsoft.com/help/5048794
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5049984
- referencehttps://support.microsoft.com/help/5049984
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5049993
- referencehttps://support.microsoft.com/help/5049993
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5048699
- referencehttps://support.microsoft.com/help/5048699
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5050048
- referencehttps://support.microsoft.com/help/5050048