CVE-2024-49132 Windows Remote Desktop Services Remote Code Execution Vulnerability
Published December 10, 2024
Information published.
Published December 10, 2024
Information published.
Published December 10, 2024
Information published.
Published December 10, 2024
To comprehensively address CVE-2024-38033, Microsoft released security updates on December 10, 2024 for all affected versions of Windows Server 2012 and Windows Server 2012 R2.
Microsoft recommends that customers running any of these products install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.
Published December 6, 2024
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024) for more information.
Published December 2, 2024
Added acknowledgements. This is an informational change only.
Published November 26, 2024
An improper access control vulnerability in [Partner.Microsoft.com](https://partner.microsoft.com/) allows an a unauthenticated attacker to elevate privileges over a network.
Published November 26, 2024
Improper neutralization of input during web page generation (‘Cross-site Scripting’) in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
Published November 26, 2024
Information published.
Published November 26, 2024
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
Published November 22, 2024
Updated CWE value. This is an informational change only.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.