CVE-2024-22211
CVSS 3.1 Score 3.7 of 10 (low)
Details
Summary
A vulnerability with the CVE ID CVE-2024-22211 has been discovered in FreeRDP, a free and open source remote desktop protocol library and clients. This vulnerability affects FreeRDP based clients, while server implementations and proxies are not affected. The vulnerability is caused by an integer overflow in `freerdp_bitmap_planar_context_reset`, which leads to a heap-buffer overflow. A malicious server could exploit this vulnerability to allocate small buffers, potentially causing out of bounds read/write operations. Upgrading to version 2.11.5 or 3.2.0 of FreeRDP is recommended as there are no known workarounds for this vulnerability. The potential danger posed by this vulnerability is low, with a base severity rating of LOW according to the CVSS score provided.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions