ZeroHour

CVE-2024-43454

mass

Path Traversal RCE in Microsoft Windows Remote Desktop Licensing Service

CVSS 3.1
7.1 high
EPSS
22%p97
Published
()
Modified
AI analysis

CVE-2024-43454 is a relative path traversal flaw (CWE-23) in the Windows Remote Desktop Licensing Service, the component that handles Remote Desktop Services client access license management. An authenticated remote attacker with low privileges can trigger it by sending a crafted request containing directory-traversal sequences that escape the service's intended path, resulting in remote code execution. Successful exploitation lets the attacker run code with the privileges of the licensing service, with high impact to system integrity and limited availability impact, while confidentiality is unaffected per the CVSS vector. Only Windows Server systems with the RD Licensing component — Windows Server 2008, 2012, 2016, 2019, 2022, and 2022 23H2 — are affected; client Windows is not listed in the provided data. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA's KEV, though a 21.9% EPSS score (97th percentile) indicates a meaningful probability of exploitation within 30 days.

What to do: Inventory which Windows Servers have the Remote Desktop Licensing role installed and apply Microsoft's security update for CVE-2024-43454 on all affected versions, prioritizing licensing servers. Until patched, restrict network access to the RD Licensing service endpoints (RPC-based) to trusted administrative hosts and low-privilege accounts. Check Microsoft's advisory for exact affected/fixed builds, since specific build numbers were not included in the source data.

Affected
microsoft windows server 2008
microsoft windows server 2012
microsoft windows server 2016
microsoft windows server 2019
microsoft windows server 2022
microsoft windows server 2022 23h2
Estimated exposure
mass≈ hundreds of thousands of Windows Server instances with the Remote Desktop Licensing component deployed (order of magnitude 10^5–10^6; exact counts unknown) — Deployment counts are not in the source data, but the affected list spans every Windows Server generation from 2008 through 2022 23H2 with an enormous aggregate installed base, and the RD Licensing role is a common (though minority)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Vendors
microsoft
Products
windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.