Lucene search

K
redhatcveRedhat.comRH:CVE-2022-41877
HistoryNov 17, 2022 - 1:57 p.m.

CVE-2022-41877

2022-11-1713:57:02
redhat.com
access.redhat.com
15
cve-2022-41877
freerdp
out-of-bounds read
drive channel
input length validation
malicious server
client
mitigation

4.6 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

0.002 Low

EPSS

Percentile

52.7%

An out-of-bounds read vulnerability was discovered in FreeRDP due to improper input length validation in the drive channel. A malicious server can trick a FreeRDP based client to read out-of-bound data and send it back to the server.

Mitigation

Do not use the drive redirection channel - command line options /drive, +drives or +home-drive.

4.6 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

0.002 Low

EPSS

Percentile

52.7%