Security Advisory

CVE-2017-2834

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-04-24 19:00:00
Last updated 2024-09-16 20:03:03
Assigner talos
CVSS score 8.8
State PUBLISHED

Description

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.