CVE-2024-32041 is a critical out-of-bounds read vulnerability affecting FreeRDP clients prior to versions 3.5.0 and 2.11.6, impacting products like Fedora. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low attack complexity, and potential for high confidentiality, integrity, and availability impacts. While no active exploitation, public exploit code, or significant community discussion has been observed, immediate patching to versions 3.5.0 or 2.11.6, or deactivating the /gfx option, is strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.6CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.5.0CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.