CVE-2024-32458
published 2024-04-22CVE-2024-32458: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.96%
78.1th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) | freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) |
| debian | freerdp3 | < freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) | freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freerdp | freerdp | < 2.11.6 | 2.11.6 |
| freerdp | freerdp | — | — |
| freerdp | freerdp | >= 3.0.0 < 3.5.0 | 3.5.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
freerdp2 vulnerabilities
osv·2025-03-25·CVSS 9.8
CVE-2024-32458 [CRITICAL] freerdp2 vulnerabilities
freerdp2 vulnerabilities
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32458)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
FreeRDP clients and servers to crash, resulting in a denial of service.
(CVE-2024-32459)
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32659,
OSV
freerdp2 vulnerabilities
osv·2025-03-11·CVSS 9.8
CVE-2024-32039 [CRITICAL] freerdp2 vulnerabilities
freerdp2 vulnerabilities
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040, CVE-2024-32041)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32458, CVE-2024-32460)
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote
OSV
freerdp2 vulnerabilities
osv·2024-04-24·CVSS 9.8
CVE-2024-22211 [CRITICAL] freerdp2 vulnerabilities
freerdp2 vulnerabilities
It was discovered that FreeRDP incorrectly handled certain context resets.
If a user were tricked into connecting to a malicious server, a remote
attacker could use this issue to cause FreeRDP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2024-22211)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker
OSV
CVE-2024-32458: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2024-04-22·CVSS 9.8
CVE-2024-32458 [CRITICAL] CVE-2024-32458: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2025-03-25·CVSS 9.8
CVE-2024-32458 [CRITICAL] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32458)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
FreeRDP clients and servers to crash, resulting in a denial of service.
(CVE-2024-32459)
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRD
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2025-03-11·CVSS 9.8
CVE-2024-32040 [CRITICAL] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040, CVE-2024-32041)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32458, CVE-2024-32460)
It was discovered that FreeRDP incorrectly handled certain memory
operations. If a use
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2024-04-24·CVSS 3.7
CVE-2024-22211 [LOW] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain context resets.
If a user were tricked into connecting to a malicious server, a remote
attacker could use this issue to cause FreeRDP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2024-22211)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were t
Red Hat
freerdp: OutOfBound Read in planar_skip_plane_rle
vendor_redhat·2024-04-22·CVSS 9.8
CVE-2024-32458 [CRITICAL] CWE-125 freerdp: OutOfBound Read in planar_skip_plane_rle
freerdp: OutOfBound Read in planar_skip_plane_rle
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).
Package: freerdp (Red Hat Enterprise Linux 10) - Not affected
Package: freerdp2 (Red Hat Enterprise Linux 10) - Not affected
Package: freerdp (Red Hat Enterprise Linux 6) - Out of support scope
Package: freerdp (Red Hat Enterprise Linux 7) - Out of support scope
Package: freerdp (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2024-32458: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c...
vendor_debian·2024·CVSS 9.8
CVE-2024-32458 [CRITICAL] CVE-2024-32458: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c...
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).
Scope: local
bookworm: resolved (fixed in 2.11.7+dfsg1-6~deb12u1)
bullseye: resolved (fixed in 2.3.0+dfsg1-2+deb11u2)
No detection rules found.
No public exploits indexed.
Securelist
Memory corruption vulnerabilities in Suricata and FreeRDP
blogs_securelist·2024-08-22·CVSS 9.8
CVE-2024-32664 [CRITICAL] Memory corruption vulnerabilities in Suricata and FreeRDP
Table of Contents
Open-source components in KasperskyOS-based products
CVE-2024-32664: out-of-bounds write in Suricata
FreeRDP vulnerabilities
CVE-2024-32041
CVE-2024-32039
CVE-2024-32040
CVE-2024-32458
CVE-2024-32459
CVE-2024-32460
Disclosure timeline
Conclusion
Authors
Dmitry Shmoylov
Evgeny Legerov
Denis Skvortsov
As a cybersecurity company, before we release our products, we perform penetration tests on them to make sure they are secure. Recently, new versions of KasperskyOS-based products were released, namely Kaspersky Thin Client (KTC) and Kaspersky IoT Secure Gateway (KISG). As part of the pre-release penetration testing, we analyzed two open-source components used in these products, namely Suricata and FreeRDP projects, and discovered several vulnerabilities, which
Securelist
Kaspersky found multiple memory corruptions in Suricata and FreeRDP
blogs_securelist·2024-08-22·CVSS 9.8
CVE-2024-32664 [CRITICAL] Kaspersky found multiple memory corruptions in Suricata and FreeRDP
Table of Contents
- Open-source components in KasperskyOS-based products
- CVE-2024-32664: out-of-bounds write in Suricata
- FreeRDP vulnerabilities
- Disclosure timeline
- Conclusion
Authors
- Dmitry Shmoylov
- Evgeny Legerov
- Denis Skvortsov
As a cybersecurity company, before we release our products, we perform penetration tests on them to make sure they are secure. Recently, new versions of KasperskyOS-based products were released, namely Kaspersky Thin Client (KTC) and Kaspersky IoT Secure Gateway (KISG). As part of the pre-release penetration testing, we analyzed two open-source components used in these products, namely Suricata and FreeRDP projects, and discovered several vulnerabilities, which we reported to the developers of the corresponding libraries, as well as sharing the
https://github.com/FreeRDP/FreeRDP/pull/10077https://github.com/FreeRDP/FreeRDP/releases/tag/2.11.6https://github.com/FreeRDP/FreeRDP/releases/tag/3.5.0https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vvr6-h646-mp4phttps://lists.fedoraproject.org/archives/list/[email protected]/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/https://lists.fedoraproject.org/archives/list/[email protected]/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/https://github.com/FreeRDP/FreeRDP/pull/10077https://github.com/FreeRDP/FreeRDP/releases/tag/2.11.6https://github.com/FreeRDP/FreeRDP/releases/tag/3.5.0https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vvr6-h646-mp4phttps://lists.debian.org/debian-lts-announce/2025/02/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/https://lists.fedoraproject.org/archives/list/[email protected]/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/
2024-04-22
Published