CVE-2020-9498 describes a memory corruption vulnerability in Apache Guacamole versions 1.1.0 and older, affecting various distributions including Debian and Fedora. This flaw arises from mishandling pointers during RDP static virtual channel processing. An attacker, by operating a malicious RDP server, could send specially-crafted PDUs to a connecting user, potentially leading to arbitrary code execution with the privileges of the guacd process. The vulnerability has a CVSS score of 6.7 (Medium) due to its high impact on confidentiality, integrity, and availability, though it requires user interaction and high attack complexity. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, despite some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0CPE matchmatch criteria | cpe:2.3:a:apache:guacamole:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.