peter bassill · operator
$ cve CVE-2018-8786 JSON

CVE-2018-8786

9.8
CRITICAL · CVSS 3.1 · EPSS 8.2% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.16% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-680
On CISA KEVno
Public exploitnone known
Published2018-11-29
Last modified2026-06-17

Affected (10)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
freerdpfreerdp
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD