Vulnerability Description
In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freerdp | Freerdp | < 2.4.0 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://github.com/FreeRDP/FreeRDP/commit/0d79670a28c0ab049af08613621aa0c267f977PatchThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/compare/2.3.2...2.4.0Release NotesThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/commit/0d79670a28c0ab049af08613621aa0c267f977PatchThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/compare/2.3.2...2.4.0Release NotesThird Party Advisory
FAQ
What is CVE-2021-37595?
CVE-2021-37595 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.
How severe is CVE-2021-37595?
CVE-2021-37595 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-37595?
Check the references section above for vendor advisories and patch information. Affected products include: Freerdp Freerdp, Microsoft Windows.