
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). A vulnerability was discovered in FreeRDP clients using /bpp:32
legacy GDI
drawing path with versions prior to 3.5.0 or 2.11.6, making them vulnerable to out-of-bounds read. The vulnerability was identified and reported by Evgeny Legerov of Kaspersky Lab (GitHub Advisory).
The vulnerability (CVE-2024-32460) is an out-of-bounds read issue in the interleaved_decompress function. The CVSS v3.1 base score is 9.8 CRITICAL according to NVD assessment, while GitHub rates it as 8.1 HIGH with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue occurs in the legacy GDI drawing path when processing certain memory operations (NVD).
If a user were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to cause FreeRDP to crash, resulting in a denial of service (Ubuntu Notice).
The vulnerability has been patched in FreeRDP versions 3.5.0 and 2.11.6. As a workaround, users can use modern drawing paths (e.g. /rfx
or /gfx
options), though this requires server side support (GitHub Advisory, FreeRDP Release).
The vulnerability was addressed promptly with releases 2.11.6 and 3.5.0, which received positive community reactions on GitHub. The releases addressing this and other security issues garnered multiple positive reactions including thumbs up, rocket, and heart emojis from the community (FreeRDP Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”