CVE-2024-38212
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-38212 is a newly disclosed vulnerability affecting the Windows Routing and Remote Access Service (RRAS). This issue permits an unauthenticated attacker to execute arbitrary code remotely, making it a critical threat. The vulnerability exists in the RRAS component's handling of RRAS web interface requests. Successful exploitation could lead to a complete system compromise, potentially providing attackers with full control over the targeted system. Microsoft is urging users to apply the forthcoming patch to mitigate this risk. Until then, organizations should restrict access to the affected component or implement additional security measures to prevent unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2022
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Affected Vendors
- Microsoft