VDB

CISA-2024-38138

CISA-2024-38138 PUBLISHED CVSS 7.5 HIGH

Reported by microsoft · Published August 13, 2024

Windows Deployment Services Remote Code Execution Vulnerability

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersions
MicrosoftWindows Server 201910.0.17763.0
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0
MicrosoftWindows Server 202210.0.20348.0
MicrosoftWindows Server 2022, 23H2 Edition (Server Core installation)10.0.25398.0
MicrosoftWindows Server 201610.0.14393.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0
MicrosoftWindows Server 2008 Service Pack 26.0.6003.0
MicrosoftWindows Server 2008 Service Pack 2 (Server Core installation)6.0.6003.0
MicrosoftWindows Server 2008 Service Pack 26.0.6003.0
MicrosoftWindows Server 2008 R2 Service Pack 16.1.7601.0
MicrosoftWindows Server 2008 R2 Service Pack 1 (Server Core installation)6.1.7601.0
MicrosoftWindows Server 20126.2.9200.0
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0
MicrosoftWindows Server 2012 R26.3.9600.0
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.9600.0
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0, 6.2.9200.0
microsoftwindows_server_23h210.0.25398.0, 10.0.25398.0
microsoftwindows_server_2008_R26.1.7601.0, 6.1.7601.0, 6.1.7601.0
MicrosoftWindows Server 20126.2.9200.0, 6.2.9200.0
MicrosoftWindows Server 201610.0.14393.0, 10.0.14393.0

…and 18 more

Timeline

  • Aug 13, 2024 CVE Published
  • Jul 10, 2025 CVE Updated
  • Apr 26, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›