CVE-2022-1736
published 2025-01-31CVE-2022-1736: Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.73%
49.9th percentile
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | ubuntu_s_gnome-control-center | < 42.1.1-2ubuntu1 | 42.1.1-2ubuntu1 |
| debian | gnome-remote-desktop | < gnome-remote-desktop 42.1.1-2 (bookworm) | gnome-remote-desktop 42.1.1-2 (bookworm) |
| gnome | gnome-remote-desktop | — | — |
| gnome | gnome-remote-desktop | — | — |
| gnome | gnome-remote-desktop | — | — |
| gnome | gnome-remote-desktop | >= 0 < 42.1.1-2 | 42.1.1-2 |
| gnome | gnome-remote-desktop | >= 0 < 42.1.1-2 | 42.1.1-2 |
| gnome | gnome-remote-desktop | >= 0 < 42.1.1-2 | 42.1.1-2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gnome-control-center: GNOME Settings could allow unintended access to network services.
vendor_redhat·2022-05-19·CVSS 9.8
CVE-2022-1736 [CRITICAL] CWE-284 gnome-control-center: GNOME Settings could allow unintended access to network services.
gnome-control-center: GNOME Settings could allow unintended access to network services.
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
A vulnerability was found in Gnome Control Center. When turning off RDP Remote Desktop Sharing with gnome-control-center, it would only turn off RDP sharing for the current session. RDP Sharing was enabled again without any additional user interaction or notification upon logging back in.
Package: gnome-control-center (Red Hat Enterprise Linux 8) - Not affected
Package: gnome-control-center (Red Hat Enterprise Linux 9) - Not affected
Ubuntu
GNOME Settings vulnerability
vendor_ubuntu·2022-05-18
CVE-2022-1736 GNOME Settings vulnerability
Title: GNOME Settings vulnerability
Summary: GNOME Settings could allow unintended access to network services.
It was discovered that GNOME Settings incorrectly handled the remote
desktop sharing configuration. When turning off desktop sharing, it may be
turned on again after rebooting, contrary to expectations.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Debian
CVE-2022-1736: gnome-remote-desktop - Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to...
vendor_debian·2022·CVSS 9.8
CVE-2022-1736 [CRITICAL] CVE-2022-1736: gnome-remote-desktop - Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to...
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
Scope: local
bookworm: resolved (fixed in 42.1.1-2)
bullseye: open
forky: resolved (fixed in 42.1.1-2)
sid: resolved (fixed in 42.1.1-2)
trixie: resolved (fixed in 42.1.1-2)
GHSA
GHSA-hh5g-6rhm-ccx9: Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default
ghsa_unreviewed·2025-01-31
CVE-2022-1736 [CRITICAL] GHSA-hh5g-6rhm-ccx9: Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
OSV
CVE-2022-1736: Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default
osv·2025-01-31·CVSS 9.8
CVE-2022-1736 [CRITICAL] CVE-2022-1736: Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
No detection rules found.
No public exploits indexed.
2025-01-31
Published