7.5

CVE-2024-38231

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx86
MicrosoftWindows Server 2008 Versionr2 HwPlatformx64
MicrosoftWindows Server 2012 Version- HwPlatformx64
MicrosoftWindows Server 2012 Versionr2 HwPlatformx64
MicrosoftWindows Server 2016 Version < 10.0.14393.7336
MicrosoftWindows Server 2019 Version < 10.0.17763.6293
MicrosoftWindows Server 2022 Version < 10.0.20348.2700
MicrosoftWindows Server 2022 23h2 Version < 10.0.25398.1128
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.92% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
secure@microsoft.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.