CVE-2024-32040 is a critical integer underflow vulnerability affecting FreeRDP clients prior to versions 3.5.0 and 2.11.6 when connecting to servers utilizing the NSC codec. With a CVSS score of 9.8, this vulnerability allows unauthenticated remote attackers to achieve high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations should prioritize patching or implementing the recommended workaround of disabling the NSC codec.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.6CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.5.0CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.