Junglewise Threat Intelligence

CVE-2024-43455: Microsoft Windows Remote Desktop Licensing Service spoofing vulnerability

CVE-2024-43455 · Severity: high · CVSS 8.8 · Published 2024-09-10

Technologies: Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2012, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows Server 2008. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows Remote Desktop Licensing Service, which manages client licenses for Remote Desktop sessions. An attacker could exploit this flaw to impersonate legitimate users or services, potentially gaining unauthorized access to sensitive data or administrative functions. This could lead to a breach of confidentiality and integrity within the server environment.

Technical details

A spoofing vulnerability exists in the Windows Remote Desktop Licensing Service due to improper input validation (CWE-20). An authenticated attacker with low privileges can exploit this over the network without user interaction. Successful exploitation allows the attacker to spoof identities, potentially leading to unauthorized access or further privilege escalation within the domain. Microsoft has released security updates to address this issue across supported Windows Server versions.

Affected products

  • Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 versions prior to 10.0.14393.7336
  • Microsoft Windows Server 2019 versions prior to 10.0.17763.6293
  • Microsoft Windows Server 2022 versions prior to 10.0.20348.2700
  • Microsoft Windows Server 2022, 23H2 versions prior to 10.0.25398.1128

Timeline

  • 2024-09-10: disclosed
  • 2024-09-10: patched: Microsoft released security updates as part of Patch Tuesday.

References

Related threats