← Back to browse · API

CVE-2024-38077

Severity
CRITICAL
CVSS
9.8
EPSS
0.75365
Risk score
65.58
CISA KEV
No
PoC
No
Published
2024-07-09
Modified
2026-02-10
First seen
2026-08-07
Aliases
EUVD-2024-37771, GHSA-9J79-XCX5-MXM4
Products
Microsoft:Windows Server 2008 Service Pack 2 6.0.6003.0 <6.0.6003.22769, Microsoft:Windows Server 2008 R2 Service Pack 1 (Server Core installation) 6.1.7601.0 <6.1.7601.27219, Microsoft:Windows Server 2008 R2 Service Pack 1 6.1.7601.0 <6.1.7601.27219, Microsoft:Windows Server 2008 Service Pack 2 (Server Core installation) 6.0.6003.0 <6.0.6003.22769, Microsoft:Windows Server 2008 Service Pack 2 6.0.6003.0 <6.0.6003.22769, Microsoft:Windows Server 2012 (Server Core installation) 6.2.9200.0 <6.2.9200.24975, Microsoft:Windows Server 2012 6.2.9200.0 <6.2.9200.24975, Microsoft:Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 <6.3.9600.22074, Microsoft:Windows Server 2012 R2 6.3.9600.0 <6.3.9600.22074, Microsoft:Windows Server 2016 (Server Core installation) 10.0.14393.0 <10.0.14393.7159, Microsoft:Windows Server 2016 10.0.14393.0 <10.0.14393.7159, Microsoft:Windows Server 2019 (Server Core installation) 10.0.17763.0 <10.0.17763.6054, Microsoft:Windows Server 2019 10.0.17763.0 <10.0.17763.6054, Microsoft:Windows Server 2022 10.0.20348.0 <10.0.20348.2582, Microsoft:Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 <10.0.25398.1009
Sources
euvd EUVD-2024-37771

Description

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

References