Microsoft published advisories for two information disclosure flaws affecting Windows Remote Desktop licensing functionality: CVE-2024-38258 in the Windows Remote Desktop Licensing Service and CVE-2022-21964 in the Remote Desktop Licensing Diagnoser. Both issues were classified as information disclosure vulnerabilities in Microsoft’s Security Update Guide and security portal.
The advisories indicate that separate components used to manage and troubleshoot Remote Desktop licensing exposed sensitive information, extending risk beyond core remote access services to supporting administrative infrastructure. Organizations using Windows Remote Desktop licensing features should review Microsoft’s guidance for the affected CVEs and apply relevant security updates to reduce exposure from unintended data disclosure.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2024-38258, an information disclosure vulnerability in the Windows Remote Desktop Licensing Service.
Microsoft published a Security Update Guide advisory for CVE-2022-21964, an information disclosure vulnerability in Remote Desktop Licensing Diagnoser.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.