Arbitrary Code Execution Vulnerability in Apache Guacamole
CVE-2023-30576

6.8MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
7 June 2023

Summary

Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process.

Affected Version(s)

Apache Guacamole 0.9.10 <= 1.5.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Schiller (Sonar)
.