
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-39318 is a security vulnerability affecting FreeRDP, specifically in its urbdrc channel implementation. The vulnerability was discovered by Team BT5 (BoB 11th) and was patched in FreeRDP version 2.9.0. This vulnerability affects versions <= 2.8.1 of FreeRDP (GitHub Advisory).
The vulnerability stems from missing input validation in the urbdrc channel of FreeRDP. The issue occurs in the libusb_udev_isoch_transfer function where a division operation is performed without proper validation of the divisor (NumberOfPackets), potentially leading to a division by zero condition (FreeRDP Commit). The vulnerability has been assigned a CVSS score of 4.8, indicating a low to moderate severity (Red Hat CVE).
When exploited, this vulnerability allows a malicious server to cause a FreeRDP-based client to crash through a division by zero error, resulting in a denial of service condition (Ubuntu Security).
The vulnerability can be exploited by a malicious server when interacting with a FreeRDP client that has USB redirection enabled. The attack vector requires the attacker to control the RDP server that the client connects to (GitHub Advisory).
The primary mitigation is to upgrade to FreeRDP version 2.9.0 or later which contains the fix for this vulnerability. As a workaround, users can avoid using the /usb redirection switch when connecting to untrusted RDP servers (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."