Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Windows Remote Desktop Services Remote Code Execution Vulnerability | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
Tue, 14 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Server 2012 Microsoft windows Server 2016 Microsoft windows Server 2019 Microsoft windows Server 2022 Microsoft windows Server 2022 23h2 Microsoft windows Server 2025 |
|
| Weaknesses | CWE-362 | |
| CPEs | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows Server 2012 Microsoft windows Server 2016 Microsoft windows Server 2019 Microsoft windows Server 2022 Microsoft windows Server 2022 23h2 Microsoft windows Server 2025 |
Fri, 13 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Dec 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
| Title | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
| Weaknesses | CWE-416 CWE-591 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published: 2024-12-10T17:49:47.953Z
Updated: 2025-05-13T15:25:50.284Z
Reserved: 2024-10-11T20:57:49.209Z
Link: CVE-2024-49128
Updated: 2024-12-13T20:24:33.804Z
Status : Modified
Published: 2024-12-12T02:04:39.870
Modified: 2025-05-13T16:15:27.703
Link: CVE-2024-49128
No data.