CVE-2024-38265: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22221Patch KB5044343 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27366Patch KB5044321 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25118Patch KB5044342 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22918Patch KB5044306 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7428Patch KB5044293 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2762Patch KB5044281 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6414Patch KB5044277 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1189Patch KB5044288
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38265?
CVE-2024-38265 is classified as a critical vulnerability allowing for remote code execution on affected systems.
How do I fix CVE-2024-38265?
To remediate CVE-2024-38265, apply the latest security patches provided by Microsoft for the affected Windows Server versions.
What systems are affected by CVE-2024-38265?
CVE-2024-38265 affects multiple versions of Windows Server including 2008 R2, 2012, 2012 R2, 2016, 2019, 2022, and 2022 23H2 Edition.
Can CVE-2024-38265 be exploited remotely?
Yes, CVE-2024-38265 can be exploited remotely by an attacker to execute arbitrary code on the affected system.
Is there a workaround for CVE-2024-38265?
While applying security patches is the recommended fix for CVE-2024-38265, disabling the affected Windows Routing and Remote Access Service can serve as a temporary workaround.