CVE-2024-38077 (CVSS 9.8) MadLicense POC
by LkStr - Saturday August 10, 2024 at 04:04 AM
#1
That's very cool:

Security researchers Ver, Lewis Lee, and Zhiniang Peng have detailed and published a proof-of-concept (PoC) exploit code for a critical vulnerability, designated as CVE-2024-38077 (CVSS 9.8) and referred to as “MadLicense,” impacting all iterations of Windows Server, spanning from 2000 to 2025. 

The Windows Remote Desktop Licensing Service (RDL), responsible for managing licenses for Remote Desktop Services, enjoys widespread deployment across a multitude of organizations. Alarmingly, researchers have determined that a minimum of 170,000 RDL services are directly exposed to the internet, rendering them readily susceptible to exploitation. Furthermore, the RDL service is commonly integrated within critical business systems and remote desktop clusters, thereby amplifying the potential ramifications of this vulnerability.

Details: Exploitable PoC Released for CVE-2024-38077: 0-Click RCE Threatens All Windows Servers
Reply
#2
hey i need its working exploit. can you contribute to it?
Reply
#3
nice! very interesting
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Scraping | https://pwnforums.st/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#4
I've not tested for the moment, but it must work so well that it has been removed from Github :

https://github.com/CloudCrowSec001/CVE-2024-38077-POC

Still available here if you need : https://web.archive.org/web/202408122227...-38077-POC
Reply
#5
If you are interested, deleted scripts of POC uploaded here :

Hidden Content
You must register or login to view this content.
Reply
#6
werwerwerwerwerwerwerwerer
Reply
#7
thats cool enough
Reply
#8
(10-04-2024, 02:50 AM)John Wrote: who have work? pm buy

I have it working, PMing you
[Image: 13c57c66-da53-4318-a2b8-cd1ccb05817e]
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  new wordpress website takeover vuln (video + poc ) zinzeur 313 27,295 03-28-2026, 02:43 AM
Last Post: toshi99
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 106 13,215 02-10-2026, 03:34 PM
Last Post: birhikayemvar
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,095 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 78 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 812 02-07-2026, 08:53 AM
Last Post: hacker0123



 Users browsing this thread: