Security Advisory

CVE-2017-2835

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-04-24 19:00:00
Last updated 2024-09-16 20:47:31
Assigner talos
State PUBLISHED

Description

An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle to trigger this vulnerability.