One Bug to Rule Them All: Stably Exploiting a Preauth RCE Vulnerability on Windows Server 2025

Black Hat Asia 2025 · Day 1 · Briefings

Overview

This presentation, "One Bug to Rule Them All," delivered by Edwards Peng, Signin, and War at Black Hat Asia, unveils a critical pre-authentication Remote Code Execution (RCE) vulnerability, CVE-2024-38077, affecting the Remote Desktop Licensing (RDL) service on Windows Server 2025. The researchers demonstrated a highly stable exploitation chain that leverages a single heap overflow bug to achieve full RCE without any prior authentication or user interaction. This research stands out by showcasing how sophisticated techniques can bypass modern Windows security mitigations, including ASLR, CFG, and LFH, using a singular flaw.

Watch on YouTube

Visual summary for One Bug to Rule Them All: Stably Exploiting a Preauth RCE Vulnerability on Windows Server 2025
Visual summary for One Bug to Rule Them All: Stably Exploiting a Preauth RCE Vulnerability on Windows Server 2025

Key moments

  1. 0:00 Introduction, speakers, and talk agenda
  2. 2:00 Significance of RDL service and pre-auth RCE threat
  3. 4:00 RDL RPC service internals and unauthenticated interfaces
  4. 5:40 Bypassing authentication to access all RPC methods
  5. 6:15 CVE-2024-38077: Heap overflow vulnerability details
  6. 7:30 Exploitation overview: one bug for address leakage and CFG bypass
  7. 9:00 Detailed explanation of heap address leakage mechanism

One Bug to Rule Them All: Stably Exploiting a Preauth RCE Vulnerability on Windows Server 2025

Speakers: Edwards Peng, Associate Professor, Huazhong University of Science and Technology, Security Researcher, Cyborg; Signin, Security Researcher; War, Security Researcher

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=CLLCcfqsuD4

Overview

This presentation, "One Bug to Rule Them All," delivered by Edwards Peng, Signin, and War at Black Hat Asia, unveils a critical pre-authentication Remote Code Execution (RCE) vulnerability, CVE-2024-38077, affecting the Remote Desktop Licensing (RDL) service on Windows Server 2025. The researchers demonstrated a highly stable exploitation chain that leverages a single heap overflow bug to achieve full RCE without any prior authentication or user interaction. This research stands out by showcasing how sophisticated techniques can bypass modern Windows security mitigations, including ASLR, CFG, and LFH, using a singular flaw.

The significance of this discovery cannot be overstated. The RDL service, a core component of the Windows Remote Desktop Services (RDS) ecosystem, is widely deployed in critical business environments and remote desktop clusters. Network scans indicate over 117,000 RDL servers are exposed online, with countless more within internal networks. A pre-authentication RCE in such a foundational service poses an extreme threat, allowing unauthenticated attackers to gain complete control over vulnerable servers. The talk highlights that despite the numerous security enhancements introduced in Windows over the past two decades, fundamental memory corruption vulnerabilities can still be exploited in novel ways to achieve devastating outcomes.

The researchers' ability to achieve RCE with "just one bug" challenges the conventional wisdom that modern Windows exploitation typically requires multiple, chained vulnerabilities to achieve both information leakage and control flow hijacking. By meticulously analyzing the RDL service's internal RPC mechanisms and the nuances of the Windows Low Fragmentation Heap (LFH), they crafted an exploit with an almost 100% success rate, proving that even a classic heap overflow, when combined with ingenious exploitation techniques, can still "rule them all" on the latest Windows Server platforms.

Background

▶ Watch: Introduction, speakers, and talk agenda (0:00)

The Remote Desktop Service (RDS) is a fundamental Windows feature enabling remote access for personal use, server management, and even remote desktop rental servers. While RDS has been a frequent target for security researchers, leading to the discovery of high-profile vulnerabilities like BlueKeep and SMBGhost in its various components, the Remote Desktop Licensing (RDL) service has received comparatively less attention. The RDL service is responsible for managing Remote Desktop licenses, a critical function within any RDS deployment. When a client connects to an RD Session Host server, that server checks its association with an RDL server to ensure proper licensing, underscoring the RDL service's importance in the overall RDS ecosystem.

The RDL service exposes its functionality through an RPC (Remote Procedure Call) interface, allowing administrators to manage licenses using tools like the RD Licensing Manager. Through reverse engineering and the use of tools like RPCView, the researchers discovered a critical design flaw: the primary RPC interface, lsrver.dll, lacks callbacks and does not have authentication flags set for its TLS RPC Connect interface. This means that anyone can call this RPC interface without authentication, serving as a crucial initial bypass for subsequent interactions.

Further analysis of the RDL RPC interfaces revealed TSRPCA Challenge Server and TSRPCA Response Server Challenge functions. While these functions appear to implement an authentication mechanism, the server's verification process is fundamentally flawed. It simply checks if the client's response matches an MD5 hash of the server challenge concatenated with a hardcoded GUID. This weak verification allows an attacker to easily forge a valid response, effectively setting the client_flags member in the connection context to 0xFFFFFFFF. This elevated flag grants the attacker full access to all RPC methods within the RDL service, setting the stage for exploiting deeper vulnerabilities.

Key Findings

▶ Watch: RDL RPC service internals and unauthenticated interfaces (4:00)

The central finding of this research is the successful exploitation of CVE-2024-38077, a pre-authentication heap overflow vulnerability within the RDL service, to achieve stable Remote Code Execution on Windows Server 2025. What makes this particularly noteworthy is the demonstration that this single vulnerability can provide both the address leakage and control flow hijacking primitives typically requiring multiple chained vulnerabilities in modern Windows exploitation scenarios.

Specifically, the heap overflow occurs in the S_DataCoding::DecodeData function, which is called by TLS RPC Telephone Register LKP when processing a License Key Pack (LKP). The decoding process, similar to Base64, uses a fixed-size heap block of 32 bytes to store the decoded results. Critically, the function lacks input size restrictions, allowing an attacker to supply an overly long LKP that causes a controllable overflow beyond the 32-byte buffer.

The researchers identified the context structure, generated during each TLS RPC Connect call, as the ideal target for this overflow. Conveniently, this structure is exactly 32 bytes in size and contains two pointer-type members: client_name and context_handle. These pointers become instrumental for the exploit:

  • client_name: Used for address leakage. By partially overwriting its lower bytes, the attacker can observe leaked heap addresses.
  • context_handle: Used for control flow hijacking. Overwriting this pointer allows redirection of program execution.

The exploitation strategy intricately weaves together heap spraying, targeted overwrites, and advanced techniques to bypass Windows' robust security mitigations:

  • ASLR (Address Space Layout Randomization) is bypassed through the heap address leakage.
  • CFG (Control Flow Guard) is circumvented by redirecting control flow to a whitelisted function, soft_call_2, within the RPC runtime (RPC RT4.dll).
  • LFH (Low Fragmentation Heap) protections are overcome by carefully manipulating the heap allocation patterns, including understanding and exploiting the LFH's delay-free mechanism to ensure reliable object placement.

The combination of these techniques results in an exploit with an almost 100% success rate on Windows Server 2025, demonstrating that even with a single, well-understood memory corruption bug, complete system compromise is achievable on the latest hardened Windows platforms.

Technical Deep Dive

▶ Watch: Bypassing authentication to access all RPC methods (5:40)

The core of this exploit lies in CVE-2024-38077, a heap overflow vulnerability residing within the S_DataCoding::DecodeData function. This function is invoked when the RDL service processes a License Key Pack (LKP) during the TLS RPC Telephone Register LKP call, typically used for telephone activation. The S_DataCoding::DecodeData function is designed to decode the LKP, a process akin to Base64 decoding, into a fixed-size 32-byte heap block. The critical flaw is the absence of input validation or size restrictions on the incoming LKP data. If the provided LKP is crafted to be sufficiently long, the DecodeData function will write beyond the allocated 32-byte buffer, resulting in a controllable heap overflow.

To exploit this, the researchers needed a target structure that was 32 bytes in size and contained exploitable pointers. They identified the context structure, which is allocated by the RDL service for each connection established via the TLS RPC Connect interface. This context structure perfectly matches the 32-byte target size and crucially contains two pointer-type members: client_name and context_handle. These members become the primitives for information leakage and control flow hijacking, respectively.

The address leakage phase leverages the client_name field. When TLS RPC Request Terms Of Certificate is called, the server stores character request information in the context. Subsequently, TLS RPC Retrieve Terms Of Certificate uses this data to generate and return a certificate to the client. The client_name field within the context structure points to an IP address stored on the heap. By performing a heap overflow that partially overwrites the lower bytes of this client_name pointer, the researchers could induce the service to return a modified address. Using Wireshark to capture the return package, they observed the value of client_name and were able to leak the heap base address plus an offset of 0x188. This process is repeated to leak other critical addresses, such as the base address of lsrver.dll and the Process Environment Block (PEB), which are essential for bypassing ASLR.

Once the necessary addresses are leaked, the next step is control flow hijacking. This is achieved by targeting the context_handle member of the context structure. The function TLS RPC Keep In Next was identified as the ideal trigger. Inside this function, if the context_type member of the context structure equals 1, a virtual function call is made using the address stored in context_handle. The heap overflow is used to overwrite the context_handle of a targeted context block with a pointer to a fake context_handle that the attacker has carefully constructed on the heap. This fake context_handle points to a crafted virtual function table (VFT), also placed on the heap.

A direct virtual function call to an attacker-controlled address would typically be blocked by Control Flow Guard (CFG). To bypass CFG, the researchers devised an ingenious strategy: they redirect control flow to the soft_call_2 function located within RPC RT4.dll, part of the RPC runtime. soft_call_2 is a CFG-whitelisted function that takes a single parameter, p_rpc_method. The p_rpc_method structure contains a dispatch table and a buffer. By forging this p_rpc_method structure and populating it with a custom dispatch table and parameters, the attackers can effectively call any function with any desired parameters. For instance, this primitive allows them to invoke LoadLibrary to load a malicious DLL from a controlled network path, thus achieving RCE.

Achieving a stable heap overflow and reliable object placement for these overwrites requires careful heap spraying and manipulation of the Low Fragmentation Heap (LFH). LFH manages heap blocks smaller than approximately 6KB, which includes the 32-byte context blocks. LFH allocates blocks from LFH subsegments, where all blocks within a subsegment are of the same size. Each subsegment includes an LFH block bitmap, a 64-bit entry map where each entry tracks the allocation status of 32 blocks. When a memory block is requested, LFH randomly selects a free block from the most recently used bitmap entry.

A key aspect of LFH exploitation is understanding its delay-free mechanism. When an LFH block is freed, it is not immediately marked as free in the bitmap. Instead, it remains in an "allocated" status and is linked to a delay-free list maintained in the subsegment header. The first 16 bytes of the freed block are reserved for this header, including a pointer to the next delay-free block and an encoded key. This encoded key, computed based on the LFH context key, block address, and free list value, is checked when the delay-free timer expires and the block is truly freed. This mechanism is designed to prevent use-after-free vulnerabilities by ensuring integrity.

The researchers' LFH manipulation strategy is as follows:

  1. Allocate sufficient connection context blocks to fill multiple bitmap entries. They ensure some entries are filled exclusively with context blocks, while others are mixed with other data.
  2. Free a small number of connection context blocks. This creates "holes" in the bitmap entries. The goal is to create these holes immediately before other existing connection context blocks.
  3. Wait for the delay-free mechanism to fully process the freed blocks. This step is crucial to avoid accidentally overwriting the header of any delay-free blocks, which would lead to a crash.
  4. Allocate a new block (the overflow block). Due to the carefully crafted heap state, there is a high probability that this new block will be placed in one of the freed holes, precisely just before an existing connection context block. This sets up the perfect scenario for the overflow to directly target and corrupt the adjacent context structure.

This intricate sequence of actions—from authenticating to the RPC service, leaking addresses, manipulating the heap, bypassing CFG, and finally hijacking control flow—demonstrates a highly sophisticated and stable approach to achieving pre-authentication RCE on Windows Server 2025 using a single memory corruption vulnerability.

Demo / Proof of Concept

▶ Watch: Exploitation overview: one bug for address leakage and CFG bypass (7:30)

The researchers provided a compelling demonstration of their exploit in action against a fully patched Windows Server 2025 instance. The live demonstration showcased the exploit chain's remarkable stability, achieving an "almost 100%" success rate.

The demonstration began with the attacker initiating the exploit, targeting the RDL service. The carefully crafted sequence of RPC calls, heap sprays, and targeted overwrites proceeded as described in the technical deep dive. The critical moment involved the successful redirection of the program's execution flow. This was visually confirmed by the server loading a malicious DLL from a path controlled by the attacker.

Upon successful execution of the malicious payload, the victim machine established an outbound connection, effectively bringing it online and linking it to the attacker's Command and Control (C2) server. This final step unequivocally proved the attainment of full, unauthenticated Remote Code Execution, highlighting the severe implications of CVE-2024-38077. The seamless and reliable nature of the demonstration underscored the practical viability and high impact of this "one bug to rule them all."

Defensive Implications

▶ Watch: Detailed explanation of heap address leakage mechanism (9:00)

The discovery and exploitation of CVE-2024-38077 carry significant defensive implications for organizations running Windows Server 2025 and earlier versions of the RDL service. The primary and most immediate action is to apply the patch for CVE-2024-38077 as soon as it becomes available. This vulnerability allows for pre-authentication RCE, making unpatched systems extremely vulnerable to remote compromise.

Beyond patching, several strategic defensive measures are crucial:

  1. Network Segmentation and Isolation: RDL servers should never be directly exposed to the internet. Implement robust network segmentation to restrict access to RDL services to only necessary internal systems. Ideally, RDL servers should reside in a highly trusted network segment, accessible only by administrative workstations or RD Session Host servers.
  2. Principle of Least Privilege: Ensure that the RDL service and any associated processes run with the absolute minimum necessary privileges. While the exploit achieves RCE, limiting the service's privileges can potentially constrain the post-exploitation impact.
  3. Aggressive Monitoring and Anomaly Detection: Implement comprehensive logging and monitoring for the RDL service. Look for unusual RPC call patterns, unexpected memory allocation or deallocation events, and any attempts to load unfamiliar DLLs. Endpoint Detection and Response (EDR) solutions should be configured to flag suspicious activity originating from the lsrver.dll process.
  4. Review RPC Interface Security: The initial authentication bypass, which allowed attackers to set client_flags to 0xFFFFFFFF due to a weak MD5-based verification, highlights a broader concern with RPC interface design. Developers and security architects should rigorously review RPC interfaces for proper authentication, authorization, and input validation to prevent similar bypasses.
  5. Disable Unnecessary Services: If the Remote Desktop Licensing service is not strictly required in an environment, it should be disabled to reduce the attack surface.
  6. Developer Education: This research serves as a stark reminder that even seemingly minor fixed-size buffer overflows can lead to full system compromise when combined with sophisticated heap manipulation and mitigation bypass techniques. Developers must prioritize secure coding practices, especially stringent input validation and bounds checking, when dealing with memory allocations and data decoding. The LFH's delay-free mechanism, while a protection, can be understood and manipulated by attackers if underlying memory safety issues exist.

In conclusion, while Microsoft continues to enhance Windows security with advanced mitigations, this research underscores that a single, well-understood memory corruption vulnerability, when exploited with precision and ingenuity, can still bypass these defenses. A multi-layered defense strategy combining timely patching, strict network controls, robust monitoring, and secure development practices is essential to protect against such advanced threats.

Key Takeaways

  • A single heap overflow vulnerability, CVE-2024-38077, in the Windows Remote Desktop Licensing (RDL) service can lead to stable pre-authentication RCE on Windows Server 2025.
  • The exploit demonstrates how to bypass modern Windows security mitigations, including ASLR, CFG, and LFH, using a single bug for both address leakage and control flow hijacking.
  • The RDL service, a critical but under-researched component of RDS, is a high-value target for attackers, with over 117,000 servers exposed online.
  • Sophisticated heap spraying and manipulation of the LFH delay-free mechanism are crucial for achieving reliable object placement and a near 100% exploitation success rate.
  • CFG bypass is achieved by redirecting control flow to the whitelisted soft_call_2 function in RPC RT4.dll, allowing arbitrary function calls like LoadLibrary.
  • Immediate patching of CVE-2024-38077, combined with strict network segmentation and monitoring of RDL servers, is paramount for defense.

About the Speaker(s)

The presentation was delivered by a team of security researchers. Edwards Peng, also known as Edwards Peng on Twitter, is an Associate Professor at Huazhong University of Science and Technology and a part-time security researcher at Cyborg. His work contributes to both academic and practical aspects of cybersecurity. Signin, a co-worker of Edwards Peng, is a dedicated security researcher whose primary focus lies in Windows security. The third speaker, War, is a security researcher with approximately three years of experience, specializing in Windows IoT and blockchain security. Together, their combined expertise contributed to the in-depth analysis and successful exploitation demonstrated in this talk.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This presentation delivers a masterclass in modern Windows exploitation, demonstrating a pre-authentication Remote Code Execution (RCE) vulnerability in the widely deployed Windows Server 2025 Remote Desktop Licensing (RDL) service. The researchers meticulously detail how a single heap overflow, CVE-2024-38077, can be leveraged to bypass ASLR, CFG, and LFH, achieving a near 100% stable RCE. This talk is a critical wake-up call, proving that even with robust mitigations, a deep understanding of system internals can still yield devastating, unauthenticated compromise on the latest Windows platforms.

Heather Calloway (CISO) — STRONG ACCEPT

This presentation on CVE-2024-38077 delivers a critical, actionable analysis of a pre-authentication RCE vulnerability in Windows Server 2025's RDL service. The researchers meticulously demonstrate how a single heap overflow can bypass modern mitigations, posing an extreme business risk to widely deployed systems. It provides clear, immediate direction for patching, network segmentation, and enhanced monitoring, making it highly valuable for security leaders and operational teams.

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025