CVE-2024-38121 is a critical Remote Code Execution vulnerability in Microsoft's Windows Routing and Remote Access Service (RRAS), impacting various Windows Server versions from 2008 to 2022. With a CVSS score of 8.8 (High), it allows unauthenticated attackers to execute arbitrary code remotely with high impact on confidentiality, integrity, and availability, though it requires user interaction. While there is no public exploit code or active exploitation reported, its presence on Microsoft's August 2024 Patch Tuesday and a single media mention indicate some level of awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* | ||
< 6.2.9200.25031CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
< 10.0.14393.7259CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.