FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade freerdp2 | Jul 30, 2024 | Apr 26, 2022 |
| Gentoo Linux | — | Upgrade net-misc/freerdp. | Oct 31, 2022 | Apr 26, 2022 |
| Suse | — | Upgrade freerdp-proxyUpgrade winpr2-develUpgrade freerdpUpgrade libwinpr2Upgrade uwac0-0-develUpgrade freerdp-waylandUpgrade freerdp-serverUpgrade libuwac0-0Upgrade libfreerdp2Upgrade freerdp-devel | Oct 26, 2022 | Apr 26, 2022 |
| Ubuntu | — | Upgrade libfreerdp-server2-2Upgrade libfreerdp-client2-2 | Jun 7, 2022 | Apr 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub