CVE-2024-43455: Windows Remote Desktop Licensing Service Spoofing Vulnerability
Windows Remote Desktop Licensing Service Spoofing Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25073Patch KB5043125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27320Patch KB5043092 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22870Patch KB5043087 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22175Patch KB5043138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7336Patch KB5043051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6293Patch KB5043050 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2700Fixed in 10.0.20348.2695Patch KB5042880 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1128Patch KB5043055
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43455?
CVE-2024-43455 is classified as a spoofing vulnerability in the Windows Remote Desktop Licensing Service.
How do I fix CVE-2024-43455?
To mitigate CVE-2024-43455, apply the appropriate security updates or patches provided by Microsoft for affected Windows Server versions.
Which systems are affected by CVE-2024-43455?
CVE-2024-43455 affects multiple versions of Windows Server, including 2022, 2019, 2016, 2012 R2, and 2008 R2.
What are the potential impacts of CVE-2024-43455?
Exploitation of CVE-2024-43455 could allow an attacker to impersonate a valid user and potentially gain unauthorized access to the system.
Is there a workaround for CVE-2024-43455 if I can't apply patches?
While the primary recommendation is to apply patches for CVE-2024-43455, temporary mitigations can include limiting access to the Remote Desktop Licensing Service to trusted networks and users.