CVE-2024-43456
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 21, 2024
CWE ID 284
Summary
CVE-2024-43456 is a newly disclosed vulnerability affecting Windows Remote Desktop Services. This issue allows unauthenticated attackers to tamper with Remote Desktop Protocol (RDP) packets, potentially leading to server compromise. The vulnerability lies in the RDP packet processing, enabling attackers to inject malicious data and execute arbitrary code on the target system. Mitigations include disabling RDP or implementing secure remote access solutions, as well as applying patches once they become available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2022
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft