Skip to content

FreeRDP Server authentication might allow invalid credentials to pass

Moderate
akallabeth published GHSA-qxm3-v2r6-vmwf Apr 26, 2022

Package

FreeRDP (C)

Affected versions

<= 2.6.1

Patched versions

2.7.0

Description

Impact

Server side authentication against a SAM file might be successful for invalid credentials if the server has configured an invalid SAM file path

  • FreeRDP based clients are not affected.
  • RDP server implementations using FreeRDP to authenticate against a SAM file are affected

Patches

Workarounds

  • Use custom authentication via HashCallback
  • Ensure the SAM database path configured is valid and the application has file handles left

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-24883

Weaknesses

No CWEs