CVE-2021-37595: Input Validation
Published Jul 27, 2021
·Updated
In FreeRDP before 2.4.0 on Windows, wfcliprdrserverfilecontentsrequest in client/Windows/wfcliprdr.c has missing input checks for a FILECONTENTSRANGE File Contents Request PDU.
Affected Software
4 affected components
FreeRDP freerdp<2.4.0
Microsoft Windows
All of the following
FreeRDP freerdp<2.4.0
Microsoft Windows
Remediation
Event History
Jul 27, 2021
CVE Published
via MITRE·11:33 PM
Data Sourced
via MITRE·11:33 PM
Description
Jul 30, 2021
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37595?
CVE-2021-37595 is a vulnerability in FreeRDP on Windows that allows attackers to send malicious requests and execute arbitrary code.
2
What is the severity of CVE-2021-37595?
CVE-2021-37595 has a severity rating of critical, with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2021-37595?
FreeRDP versions up to but excluding 2.4.0 are affected by CVE-2021-37595.
4
How can I fix CVE-2021-37595?
To fix CVE-2021-37595, it is recommended to update FreeRDP to version 2.4.0 or later.
5
What is the Common Weakness Enumeration (CWE) for CVE-2021-37595?
The CWE for CVE-2021-37595 is CWE-20, which refers to improper input validation.