CVE-2024-43582

Published Oct 8, 2024

Last updated 2 years ago

CVSS high 8.1
Server
Rdp

Overview

Description
Remote Desktop Protocol Server Remote Code Execution Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_21h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2019, windows_server_2022, windows_server_2022_23h2

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
secure@microsoft.com
CWE-416

Social media

Hype score
Not currently trending
  1. Microsoft Remote Desktop Protocol mit CVSS 8.1 Sicherheitslücke Microsoft listet die hochgefährliche Schwachstelle CVE-2024-43582 auf, eine Sicherheitslücke die Remote-Codeausführung erlaubt im Remote Desktop Protocol Server. https://t.co/HQCzXNOqX2 https://t.co/ruljv7Dsi1

    @B2bCyber

    36 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. https://t.co/3s0dptBRzJ Microsoft Remote Desktop Protocol with CVSS 8.1 vulnerability Microsoft lists the highly dangerous vulnerability CVE-2024-43582, a security hole that allows remote code execution in the Remote Desktop Protocol Server. The CVSS score is 8.1. Microsoft s…

    @B2bCyber

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-43582 Remote Desktop Protocol Server Remote Code Execution Vulnerability https://t.co/QJHkpAzCMH

    @Dinosn

    9 Jun 2026

    1312 Impressions

    4 Retweets

    13 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-43582 is classified as a Remote Code Execution (RCE) vulnerability. This means that an attacker can execute arbitrary code on an affected system simply by sending specially crafted RDP requests. The craziest part? They don’t even need to authenticate!

    @Bungufred

    22 Oct 2024

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-43582: RCE in RDP Servers, 8.1 rating❗️ A use after free vulnerability in some RDP servers could allow an attacker to carry out remote code execution. The patch is already available. 👉 Dork: protocol:rdp Vendor's advisory: https://t.co/JOSbleJB7W #rdp تیم سورین

    @akaclandestine

    19 Oct 2024

    953 Impressions

    0 Retweets

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.