cbcvebase.
CVE-2023-40181
published 2023-08-31

CVE-2023-40181: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer-Underflow…

PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.43%
70.1th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer-Underflow leading to Out-Of-Bound Read in the `zgfx_decompress_segment` function. In the context of `CopyMemory`, it's possible to read data beyond the transmitted packet range and likely cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfreerdp2< freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
freerdpfreerdp< 2.11.02.11.0
freerdpfreerdp
freerdpfreerdp

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_ubuntu5.9MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.