xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-07 22:15
Updated : 2022-02-17 05:15
NVD link : CVE-2022-23613
Mitre link : CVE-2022-23613
JSON object : View
Products Affected
neutrinolabs
- xrdp
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)
