CVE Vulnerabilities

CVE-2024-49120

Insecure Default Variable Initialization

Published: Dec 12, 2024 | Modified: Jan 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Windows Remote Desktop Services Remote Code Execution Vulnerability

Weakness

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Affected Software

NameVendorStart VersionEnd Version
Windows_server_2012Microsoft- (including)- (including)
Windows_server_2012Microsoftr2 (including)r2 (including)
Windows_server_2016Microsoft*10.0.14393.7606 (excluding)
Windows_server_2019Microsoft*10.0.17763.6659 (excluding)
Windows_server_2022Microsoft*10.0.20348.2966 (excluding)
Windows_server_2022_23h2Microsoft*10.0.25398.1308 (excluding)
Windows_server_2025Microsoft*10.0.26100.2605 (excluding)

Potential Mitigations

References