CVE-2023-39352 is a critical out-of-bounds write vulnerability affecting FreeRDP, an open-source Remote Desktop Protocol client, and its derivatives in Debian and Fedora. This flaw occurs due to invalid offset validation, specifically when rectangle dimensions match surface dimensions, leading to a crash. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk with network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there are no known active exploits, public exploit code, or Metasploit modules, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness among security researchers. Users are strongly advised to upgrade to FreeRDP versions 2.11.0 or 3.0.0-beta3 immediately, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.0CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:3.0.0:beta1:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:3.0.0:beta2:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.