Critical SEVERITY — Vulnerability

CVE-2024-38077: Remote Desktop Licensing Service RCE (9.8)

The critical vulnerability in the RDL service allows unauthenticated code execution over the network. All WS2012–2022 are affected.

Platform
Windows Server
Version
2022
CVE Record
CVE-2024-38077
CVSS Score
9.8/10
Advisory
KB5041160
Published
09 July 2026
Views
13
Primary source: Review the official advisory at msrc.microsoft.com Kaynağa Git

Summary

CVE-2024-38077 is a buffer overflow vulnerability in the Windows Remote Desktop Licensing (RDL) service. CVSS 9.8 — allows network-based, unauthenticated code execution as SYSTEM.

Affected systems

All Windows Server versions with the RDL role installed (2012 → 2022). In our customer environments using RDS this role is active on many servers.

Actions

  • The July cumulative update (KB5041160 and later) should be applied urgently
  • Unused RDL role should be removed entirely
  • Restrict 135/TCP access to the management VLAN only
Remote Desktop Licensing TermServLicensing

Windows Server — Related Advisories

VIEW ALL →