Vulnerability-and-Exploit-Analysis CVE-2024-38063 CVE-2024-38077 CVE-2024-43491

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Published 9 Jul 2024Updated 17 Jun 20265 sources
CVSS 9.8 ✓ VERIFIED REFERENCE

What happened

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Affected versions

Windows Server 2019: 10.0.17763.0 through before 10.0.17763.6054 (custom); 10.0.20348.0 through before 10.0.20348.2582 (custom); 10.0.25398.0 through before 10.0.25398.1009 (custom); 10.0.14393.0 through before 10.0.14393.7159 (custom); 6.0.6003.0 through before 6.0.6003.22769 (custom); 6.1.7601.0 through before 6.1.7601.27219 (custom); 6.2.9200.0 through before 6.2.9200.24975 (custom); 6.3.9600.0 through before 6.3.9600.22074 (custom) Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references