Vulnerability record · CVE-2024-38077 · published 9 July 2024
CVE-2024-38077: Windows Remote Desktop Licensing Service heap buffer overflow RCE
Microsoft · Windows Server 2008
The Windows Remote Desktop Licensing Service contains a heap-based buffer overflow that allows remote code execution. The flaw is network reachable with no privileges or user interaction required, and it affects multiple Windows Server releases. It matters because a successful exploit can fully compromise the licensing service host.
Description
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and a very high EPSS probability make this a top remediation priority despite no KEV listing.
What it is
The Windows Remote Desktop Licensing Service contains a heap-based buffer overflow that allows remote code execution. The flaw is network reachable with no privileges or user interaction required, and it affects multiple Windows Server releases. It matters because a successful exploit can fully compromise the licensing service host.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected server, gaining full control of confidentiality, integrity and availability.
Attack surface
Reached over the network via the Remote Desktop Licensing Service; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high at 0.841 (99.68th percentile), indicating elevated likelihood of exploitation. References are limited to Microsoft patch and vendor advisory pages.
What to do
- Apply the Microsoft security update for CVE-2024-38077 on all affected Windows Server versions immediately.
- If the Remote Desktop Licensing role is not required, disable or remove it to eliminate exposure.
- Restrict network access to the RDL service port (TCP 135/RPC and related dynamic ports) to trusted hosts only.
- Monitor Microsoft advisories for updated guidance and any revised patches.
- Segment or isolate servers running the licensing role to limit lateral movement if compromised.
Detection
- Monitor for unexpected crashes or restarts of the Remote Desktop Licensing Service (TermServLicensing).
- Alert on anomalous RPC or network traffic to the licensing service from untrusted sources.
- Review Windows event logs and process creation for unusual child processes spawned by the licensing service.
- Track exploitation attempts via IDS/IPS signatures targeting the RDL service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077 | PatchVendor Advisory |
Track CVE-2024-38077 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-38077), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.