CVE-2024-43456
Windows Remote Desktop Services Tampering Vulnerability
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.74%
- CWE
- CWE-284
- Published
- 2024-10-08
- Last modified
- 2026-08-19
Affected products
- Microsoft Windows Server 2019
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows Server 2022
- Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)
- Microsoft Windows Server 2016
- Microsoft Windows Server 2016 (Server Core installation)
- Microsoft Windows Server 2008 R2 Service Pack 1
- Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)
Weakness type
Related vulnerabilities
- CVE-2026-65182 — Apache Tomcat: Bypass longest prefix security constraint
- CVE-2026-76607 — Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2
- CVE-2026-54745 — Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true
- CVE-2026-20315 — Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities
- CVE-2026-20192 — Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities
- CVE-2026-77553 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-77536 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-77534 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f