Use of uninitialized resource in Windows Server - CVE-2024-38260

 

Use of uninitialized resource in Windows Server - CVE-2024-38260

Published: September 10, 2024


Vulnerability identifier: #VU97009
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38260
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to usage of uninitialized resources in Windows Remote Desktop Licensing Service. A remote user can pass specially crafted data to the application, trigger uninitialized usage of resources and execute arbitrary code on the target system.


Affected software

Windows Server

How to mitigate CVE-2024-38260

Install updates from vendor's website.

Windows Server - addressed in versions 2008 R2 6.1.7601.27320, 2012 R2 6.3.9600.22175, 2012 6.2.9200.25073, 2016 10.0.14393.7336, 2019 10.0.17763.6293, 2022 23H2 10.0.25398.1128, 2022 10.0.20348.2695, 2022 10.0.20348.2700

External References

Related Security Bulletins