CVE-2024-43454
massPath Traversal RCE in Microsoft Windows Remote Desktop Licensing Service
CVE-2024-43454 is a relative path traversal flaw (CWE-23) in the Windows Remote Desktop Licensing Service, the component that handles Remote Desktop Services client access license management. An authenticated remote attacker with low privileges can trigger it by sending a crafted request containing directory-traversal sequences that escape the service's intended path, resulting in remote code execution. Successful exploitation lets the attacker run code with the privileges of the licensing service, with high impact to system integrity and limited availability impact, while confidentiality is unaffected per the CVSS vector. Only Windows Server systems with the RD Licensing component — Windows Server 2008, 2012, 2016, 2019, 2022, and 2022 23H2 — are affected; client Windows is not listed in the provided data. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA's KEV, though a 21.9% EPSS score (97th percentile) indicates a meaningful probability of exploitation within 30 days.
What to do: Inventory which Windows Servers have the Remote Desktop Licensing role installed and apply Microsoft's security update for CVE-2024-43454 on all affected versions, prioritizing licensing servers. Until patched, restrict network access to the RD Licensing service endpoints (RPC-based) to trusted administrative hosts and low-privilege accounts. Check Microsoft's advisory for exact affected/fixed builds, since specific build numbers were not included in the source data.
| microsoft windows server 2008 | — |
| microsoft windows server 2012 | — |
| microsoft windows server 2016 | — |
| microsoft windows server 2019 | — |
| microsoft windows server 2022 | — |
| microsoft windows server 2022 23h2 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- Vendors
- microsoft
- Products
- windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-23
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.