icon

We found results for “

CVE-2022-24883

Date: April 25, 2022

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a "SAM" file might be successful for invalid credentials if the server has configured an invalid "SAM" file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a "SAM" file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via "HashCallback" and/or ensure the "SAM" database path configured is valid and the application has file handles left.

Language: C

Severity Score

Related Resources (17)

Severity Score

Weakness Type (CWE)

Improper Authentication

CWE-287

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): PARTIAL
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us