CVE-2024-32040
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Apr 22, 2024
Updated: Jun 10, 2024
CWE ID 191
Summary
CVE-2024-32040 is a vulnerability affecting FreeRDP, a free Remote Desktop Protocol implementation. Clients using versions prior to 3.5.0 or 2.11.6, and connecting to servers using the NSC codec, are at risk due to an integer underflow issue. This flaw can be exploited to potentially gain unauthorized access. The vulnerability has been patched in versions 3.5.0 and 2.11.6. As a temporary measure, users are advised to disable the NSC codec (e.g. by using `-nsc`).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share