Improper Authorization (CWE-285)
Windows Remote Desktop Licensing Service is vulnerable to a denial of service attack. This vulnerability affects various versions of Windows Server, including Server 2008, 2012, 2016, 2019, 2022, and 2022 23H2. The vulnerability is due to improper authorization (CWE-285) in the Remote Desktop Licensing Service.
An attacker can exploit this vulnerability to cause a denial of service, potentially disrupting the availability of the Remote Desktop Licensing Service. This could affect organizations relying on Remote Desktop Services, particularly in enterprise environments. The attack vector is network-based, requires no user interaction, and can be executed with low attack complexity. The vulnerability only impacts the availability of the system, with no effects on integrity or confidentiality.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Yes, a patch is available. Microsoft has released updates to address this vulnerability. The patches were made available on September 10, 2024.
1. Apply the latest security updates provided by Microsoft for the affected Windows Server versions. 2. For Windows Server 2019, update to a version newer than 10.0.17763.6293. 3. For Windows Server 2022 23H2, update to a version newer than 10.0.25398.1128. 4. For Windows Server 2016, update to a version newer than 10.0.14393.7336. 5. For Windows Server 2022, update to a version newer than 10.0.20348.2700. 6. If immediate patching is not possible, consider limiting network access to the Remote Desktop Licensing Service to trusted IP addresses only. 7. Monitor for any unusual activity or attempts to exploit this vulnerability in your network logs. 8. Ensure that your overall security posture is robust, including keeping all systems and software up to date, implementing strong access controls, and following the principle of least privilege.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (92169)
A CVSS base score of 6.5 has been assigned.
Feedly found the first article mentioning CVE-2024-38231. See article
Feedly estimated the CVSS score as HIGH
NVD published the first details for CVE-2024-38231
Feedly estimated the CVSS score as MEDIUM
EPSS Score was set to: 0.04% (Percentile: 14.1%)
A CVSS base score of 7.5 has been assigned.
EPSS Score was set to: 0.06% (Percentile: 28.5%)