FreeRDP Vulnerability Could Lead to Crash and NULL Access
CVE-2024-32661

7.5HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
23 April 2024

What is CVE-2024-32661?

FreeRDP, an open-source implementation of the Remote Desktop Protocol, is exposed to a vulnerability that could allow for a NULL access resulting in potential application crashes. This issue affects all FreeRDP clients before version 3.5.1. Users are strongly encouraged to upgrade to version 3.5.1 or later, which includes the necessary patch to resolve this vulnerability. Currently, there are no known workarounds for this issue, emphasizing the importance of keeping software up to date to ensure continued security and stability.

Affected Version(s)

FreeRDP < 3.5.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-32661 : FreeRDP Vulnerability Could Lead to Crash and NULL Access