CVE-2024-38071 is a Denial of Service vulnerability affecting the Windows Remote Desktop Licensing Service across various Windows Server versions, including 2008 through 2022. With a CVSS score of 7.5 (HIGH), this vulnerability can be exploited remotely without authentication, allowing an unauthenticated attacker to disrupt the service. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), its high EPSS score and FAUCET Risk Score of 91/100 indicate a significant potential for future exploitation, warranting immediate patching as highlighted by its inclusion in Microsoft's July 2024 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.