FreeRDP Vulnerability: Integer Overflow and Out-of-Bounds Write
CVE-2024-32039
What is CVE-2024-32039?
The vulnerability affects FreeRDP, an open-source implementation of the Remote Desktop Protocol, specifically impacting clients running versions prior to 3.5.0 and 2.11.6. This issue arises from an integer overflow and an out-of-bounds write, which could potentially allow attackers to execute arbitrary code or disrupt service. Users are advised to upgrade to the patched versions to mitigate risks. As a temporary measure, it is recommended to avoid the use of /gfx
options in configurations, opting instead for parameters like /bpp:32
or disabling /rfx
, which is enabled by default. Keeping software updated and adhering to security advisories is essential for maintaining a secure computing environment.
Affected Version(s)
FreeRDP >= 3.0.0, 3.5.0 >= 3.0.0, 3.5.0
FreeRDP < 2.11.6 < 2.11.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved