CVE-2024-38077: Remote Desktop Licensing Service RCE (9.8)
The critical vulnerability in the RDL service allows unauthenticated code execution over the network. All WS2012–2022 are affected.
The critical vulnerability in the RDL service allows unauthenticated code execution over the network. All WS2012–2022 are affected.
CVE-2024-38077 is a buffer overflow vulnerability in the Windows Remote Desktop Licensing (RDL) service. CVSS 9.8 — allows network-based, unauthenticated code execution as SYSTEM.
All Windows Server versions with the RDL role installed (2012 → 2022). In our customer environments using RDS this role is active on many servers.
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=<cmd> can cause exec.CommandContext("ss
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.