CVE-2024-38212

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 22, 2024
CWE ID 122

Summary

CVE-2024-38212 is a newly disclosed vulnerability affecting the Windows Routing and Remote Access Service (RRAS). This issue permits an unauthenticated attacker to execute arbitrary code remotely, making it a critical threat. The vulnerability exists in the RRAS component's handling of RRAS web interface requests. Successful exploitation could lead to a complete system compromise, potentially providing attackers with full control over the targeted system. Microsoft is urging users to apply the forthcoming patch to mitigate this risk. Until then, organizations should restrict access to the affected component or implement additional security measures to prevent unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2022
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019

Affected Vendors

  • Microsoft