FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 26, 2022 |
| Debian | — | Upgrade freerdp2 | Nov 20, 2023 | Apr 26, 2022 |
| Gentoo Linux | — | Upgrade net-misc/freerdp. | Oct 31, 2022 | Apr 26, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade freerdpUpgrade libwinprUpgrade freerdp-libs | Jun 22, 2022 | Apr 26, 2022 |
| Suse | — | Upgrade freerdp-proxyUpgrade uwac0-0-develUpgrade freerdpUpgrade freerdp-develUpgrade freerdp-serverUpgrade libfreerdp2Upgrade libwinpr2Upgrade freerdp-waylandUpgrade winpr2-develUpgrade libuwac0-0 | Oct 26, 2022 | Apr 26, 2022 |
| Ubuntu | — | Upgrade libfreerdp-client2-2Upgrade libfreerdp-server2-2 | Jun 7, 2022 | Apr 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub