Arbitrary Code Execution Vulnerability in Apache Guacamole Terminal Emulator
CVE-2024-35164

6.8MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 July 2025

What is CVE-2024-35164?

The terminal emulator in Apache Guacamole versions 1.5.5 and earlier is susceptible to an arbitrary code execution vulnerability due to insufficient validation of console codes received from servers over text-based protocols such as SSH. If a malicious actor gains access to a text-based connection, they may exploit this weakness by sending specially-crafted sequences of console codes, potentially leading to the execution of arbitrary code with the privileges of the guacd process. To mitigate this security issue, users are strongly advised to upgrade to version 1.6.0, which addresses this vulnerability.

Affected Version(s)

Apache Guacamole 0.8.0 <= 1.5.5

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tizian Seehaus (Tibotix)
.
CVE-2024-35164 : Arbitrary Code Execution Vulnerability in Apache Guacamole Terminal Emulator