CVE-2024-38077: Remote Desktop Licensing Service RCE (9.8)
The critical vulnerability in the RDL service allows unauthenticated code execution over the network. All WS2012–2022 are affected.
The critical vulnerability in the RDL service allows unauthenticated code execution over the network. All WS2012–2022 are affected.
CVE-2024-38077 is a buffer overflow vulnerability in the Windows Remote Desktop Licensing (RDL) service. CVSS 9.8 — allows network-based, unauthenticated code execution as SYSTEM.
All Windows Server versions with the RDL role installed (2012 → 2022). In our customer environments using RDS this role is active on many servers.
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.