Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-39355
HistoryAug 31, 2023 - 8:15 p.m.

Design/Logic Flaw

2023-08-3120:15:00
PRIOn knowledge base
www.prio-n.com
9
freerdp
use-after-free
rdp
vulnerability

9.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing RDPGFX_CMDID_RESETGRAPHICS packets. If context->maxPlaneSize is 0, context->planesBuffer will be freed. However, without updating context->planesBuffer, this leads to a Use-After-Free exploit vector. In most environments this should only result in a crash. This issue has been addressed in version 3.0.0-beta3 and users of the beta 3.x releases are advised to upgrade. There are no known workarounds for this vulnerability.

9.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.9%