Record summary

CVE-2024-49085 has a selected CVSS score of 8.8 (high).

Description

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 13, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 16
ProductSourceVersion rangeStatus
CVE List6.0.6003.0 to < 6.0.6003.23016affected
CVE List6.1.7601.0 to < 6.1.7601.27467affected

Windows Server 2008 R2 Service Pack 1 (Server Core installation)

Browse Microsoft / Windows Server 2008 R2 Service Pack 1 (Server Core installation)
CVE List6.1.7601.0 to < 6.1.7601.27467affected

Windows Server 2008 Service Pack 2 (Server Core installation)

Browse Microsoft / Windows Server 2008 Service Pack 2 (Server Core installation)
CVE List6.0.6003.0 to < 6.0.6003.23016affected
CVE List6.2.9200.0 to < 6.2.9200.25222affected

Windows Server 2012 (Server Core installation)

Browse Microsoft / Windows Server 2012 (Server Core installation)
CVE List6.2.9200.0 to < 6.2.9200.25222affected
CVE List6.3.9600.0 to < 6.3.9600.22318affected

Windows Server 2012 R2 (Server Core installation)

Browse Microsoft / Windows Server 2012 R2 (Server Core installation)
CVE List6.3.9600.0 to < 6.3.9600.22318affected
CVE List10.0.14393.0 to < 10.0.14393.7606affected

Windows Server 2016 (Server Core installation)

Browse Microsoft / Windows Server 2016 (Server Core installation)
CVE List10.0.14393.0 to < 10.0.14393.7606affected
CVE List10.0.17763.0 to < 10.0.17763.6659affected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.17763.0 to < 10.0.17763.6659affected

References

2