CVE Vulnerabilities

CVE-2024-49120

Insecure Default Variable Initialization

Published: Dec 12, 2024 | Modified: Jan 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Windows Remote Desktop Services Remote Code Execution Vulnerability

Weakness

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Affected Software

Name Vendor Start Version End Version
Windows_server_2012 Microsoft - (including) - (including)
Windows_server_2012 Microsoft r2 (including) r2 (including)
Windows_server_2016 Microsoft * 10.0.14393.7606 (excluding)
Windows_server_2019 Microsoft * 10.0.17763.6659 (excluding)
Windows_server_2022 Microsoft * 10.0.20348.2966 (excluding)
Windows_server_2022_23h2 Microsoft * 10.0.25398.1308 (excluding)
Windows_server_2025 Microsoft * 10.0.26100.2605 (excluding)

Potential Mitigations

References