CVE-2024-49120CriticalCVSS 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

Published
December 10, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition.

How could an attacker exploit this vulnerability? An attacker could successfully exploit this vulnerability by connecting to a system with the Remote Desktop Gateway role, triggering the race condition to create a use-after-free scenario, and then leveraging this to execute arbitrary code.

🎯 Affected products13

  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022, 23H2 Edition (Server Core installation)
  • Windows Server 2025
  • Windows Server 2025 (Server Core installation)

✅ Remediation

KB5050008 (Security Update) — fixed build 10.0.17763.6775 KB5049983 (Security Update) — fixed build 10.0.20348.3091 KB5048800 (SecurityHotpatchUpdate) — fixed build 10.0.20348.2908 KB5050009 (Security Update) — fixed build 10.0.26100.2894 KB5048794 (SecurityHotpatchUpdate) — fixed build 10.0.26100.2528 KB5049984 (Security Update) — fixed build 10.0.25398.1369 KB5049993 (Security Update) — fixed build 10.0.14393.7699 KB5048699 (Monthly Rollup) — fixed build 6.2.9200.25222 KB5050048 (Monthly Rollup) — fixed build 6.3.9600.22371

🔗 References (19)