CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22175Patch KB5043138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4169Patch KB5043076 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7336Patch KB5043051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20766Patch KB5043083 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4894Patch KB5043064 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4894Patch KB5043064 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.1742Patch KB5043080 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4169Patch KB5043076 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1128Patch KB5043055 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2700Fixed in 10.0.20348.2695Patch KB5042880 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6293Patch KB5043050 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.3197Patch KB5043067
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38240?
CVE-2024-38240 has been classified with high severity due to its potential for elevation of privilege.
How do I fix CVE-2024-38240?
To fix CVE-2024-38240, users should apply the latest security updates provided by Microsoft for their affected versions of Windows.
Which versions of Windows are affected by CVE-2024-38240?
CVE-2024-38240 affects various versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2, 24H2), and Windows Server editions.
What type of vulnerability is CVE-2024-38240?
CVE-2024-38240 is an elevation of privilege vulnerability found in the Windows Remote Access Connection Manager.
Can CVE-2024-38240 be exploited remotely?
Yes, CVE-2024-38240 can potentially be exploited remotely by an attacker to gain elevated privileges on the affected system.