CVE-2023-30576 is a critical use-after-free vulnerability affecting Apache Guacamole versions 0.9.10 through 1.5.1, specifically within the RDP audio input buffer handling. This flaw could enable an unauthenticated attacker to achieve arbitrary code execution with guacd process privileges due to timing-dependent memory referencing. With a CVSS score of 8.1 (HIGH), it presents a significant risk, though its exploitability is considered high complexity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.0, < 1.5.2CPE matchmatch criteria | cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:* | ||
>= 0.9.10, <= 1.5.1CPE match | cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.