CVE-2024-22211

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Jan 19, 2024
Updated: Feb 17, 2024
CWE ID 190
CWE ID 122

Summary

A vulnerability with the CVE ID CVE-2024-22211 has been discovered in FreeRDP, a free and open source remote desktop protocol library and clients. This vulnerability affects FreeRDP based clients, while server implementations and proxies are not affected. The vulnerability is caused by an integer overflow in `freerdp_bitmap_planar_context_reset`, which leads to a heap-buffer overflow. A malicious server could exploit this vulnerability to allocate small buffers, potentially causing out of bounds read/write operations. Upgrading to version 2.11.5 or 3.2.0 of FreeRDP is recommended as there are no known workarounds for this vulnerability. The potential danger posed by this vulnerability is low, with a base severity rating of LOW according to the CVSS score provided.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-22211 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions