CVE-2018-1000852: Medium severity freerdp vulnerability

Published Dec 20, 2018
·
Updated

FreeRDP 2.0.0-rc3 contains an out of bounds read vulnerability in drdynvcprocesscapabilityrequest function in channels/drdynvc/client/drdynvcmain.c file. To exploit this RDPClient must connect to the rdp server with the echo option. This can lead to a two-byte outbound reading from the client memory.

References: https://github.com/FreeRDP/FreeRDP/issues/4866

Upstream Patch: https://github.com/FreeRDP/FreeRDP/pull/4871/commits/baee520e3dd9be6511c45a14c5f5e77784de1471

Other sources

FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvcmain.c, drdynvcprocesscapabilityrequest that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.

Launchpad

Affected Software

10 affected componentsFixes available
debian/freerdp2
2.3.0+dfsg1-2+deb11u12.3.0+dfsg1-2+deb11u32.10.0+dfsg1-1
FreeRDP freerdp<2.0.0
FreeRDP freerdp=2.0.0
FreeRDP freerdp=2.0.0-rc0
FreeRDP freerdp=2.0.0-rc1
FreeRDP freerdp=2.0.0-rc2
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
Fedoraproject Fedora=28

Event History

Dec 20, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Dec 21, 2018
Data Sourced
via Red Hat·08:31 PM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:23 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·03:44 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2018-1000852?

CVE-2018-1000852 has a moderate severity rating due to its potential to leak sensitive information.

2

How do I fix CVE-2018-1000852?

To fix CVE-2018-1000852, upgrade FreeRDP to version 2.3.0 or later, or apply any available patches provided by your distribution.

3

Which versions of FreeRDP are affected by CVE-2018-1000852?

FreeRDP versions prior to 2.3.0 and any release candidate versions from 2.0.0-rc0 to 2.0.0-rc3 are affected by CVE-2018-1000852.

4

Can CVE-2018-1000852 be exploited without user action?

Yes, CVE-2018-1000852 can be exploited if the RDP Client connects to an RDP server with the echo option enabled.

5

What impact does CVE-2018-1000852 have on systems?

Exploitation of CVE-2018-1000852 can lead to an out-of-bounds read, potentially revealing sensitive data from the client.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203