Lucene search

K
osvGoogleOSV:CVE-2022-23481
HistoryDec 09, 2022 - 6:15 p.m.

CVE-2022-23481

2022-12-0918:15:16
Google
osv.dev
10
xrdp
out of bound read
vulnerability
microsoft remote desktop protocol
rdp
upgrade
software

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.2%

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.