CVE-2022-24882: Server side NTLM does not properly check parameters in FreeRDP
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-24882?
CVE-2022-24882 is a vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP), where NT LAN Manager (NTLM) authentication does not properly abort when an empty password is provided.
Which software versions are affected by CVE-2022-24882?
Versions of FreeRDP prior to 2.7.0 are affected by CVE-2022-24882.
How severe is CVE-2022-24882?
CVE-2022-24882 has a severity score of 7.5 (critical).
How can I fix CVE-2022-24882?
To fix CVE-2022-24882, upgrade to FreeRDP version 2.7.0 or later.
Where can I find more information about CVE-2022-24882?
More information about CVE-2022-24882 can be found at the following references: - [GitHub Pull Request #7750](https://github.com/FreeRDP/FreeRDP/pull/7750) - [FreeRDP 2.7.0 Release](https://github.com/FreeRDP/FreeRDP/releases/tag/2.7.0) - [GitHub Security Advisory GHSA-6x5p-gp49-3jhh](https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6x5p-gp49-3jhh)