Remote Desktop Client Vulnerability in FreeRDP
CVE-2024-32660

7.5HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
23 April 2024

What is CVE-2024-32660?

FreeRDP, a widely-used implementation of the Remote Desktop Protocol, has a significant vulnerability that allows an attacker to crash the FreeRDP client. This can occur when a malicious server sends an invalid allocation size request that exceeds the expected limits. The problematic versions of FreeRDP are those released prior to 3.5.1, which has since addressed this issue through a patch. Users relying on FreeRDP should upgrade to version 3.5.1 or later to mitigate this security risk, as there are currently no known workarounds available.

Affected Version(s)

FreeRDP < 3.5.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-32660 : Remote Desktop Client Vulnerability in FreeRDP