Описание
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
A flaw was found in FreeRDP. An uninitialized heap memory disclosure vulnerability exists in the urbdrc USB redirection channel. A malicious Remote Desktop Protocol (RDP) server can exploit this by inducing failing USB transfers, allowing it to read uninitialized heap memory from the client. This information disclosure can defeat Address Space Layout Randomization (ASLR), potentially enabling remote code execution when chained with other memory corruption vulnerabilities.
Меры по смягчению последствий
To reduce exposure, avoid connecting to untrusted RDP servers or disable the FreeRDP USB redirection channel if it is not required. When using the xfreerdp client, ensure that USB redirection is not enabled. This can be done by omitting the /usb or /usb-redir command-line options, or by explicitly disabling the urbdrc channel through FreeRDP configuration if available. Disabling this feature will prevent the redirection of USB devices to the remote session.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
[GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path]
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
FreeRDP versions before 3.31.0 contain an uninitialized heap memory di ...
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
EPSS
8.8 High
CVSS3