Lucene search

K
freebsdFreeBSDFC2A9541-8893-11EC-9D01-80EE73419AF3
HistoryJan 23, 2022 - 12:00 a.m.

xrdp -- privilege escalation

2022-01-2300:00:00
vuxml.freebsd.org
14
integer underflow
heap overflow
xrdp sesman server
privilege escalation
unauthenticated attacker
root access
remote access

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.8%

xrdp project reports:

An integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is accessible to a sesman server (listens by default on localhost when installing xrdp, but can be remote if configured otherwise) to execute code as root.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchxrdp= 0.9.17,1UNKNOWN
FreeBSDanynoarchxrdp< 0.9.18.1,1UNKNOWN
FreeBSDanynoarchxrdp-devel= 0.9.17,1UNKNOWN
FreeBSDanynoarchxrdp-devel< 0.9.18.1,1UNKNOWN

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.8%