CVE-2022-23613
Privilege escalation on xrdp
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.
xrdp es un servidor de protocolo de escritorio remoto (RDP) de código abierto. En las versiones afectadas, un desbordamiento de enteros que conlleva a un desbordamiento de pila en el servidor sesman permite a cualquier atacante no autenticado que sea capaz de acceder localmente a un servidor sesman ejecutar código como root. Esta vulnerabilidad ha sido parcheada en la versión 0.9.18.1 y superiores. Es aconsejado a usuarios que se actualicen. No hay medidas de mitigación adicionales conocidas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-19 CVE Reserved
- 2022-02-07 CVE Published
- 2023-09-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-191: Integer Underflow (Wrap or Wraparound)
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-8h98-h426-xf32 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/neutrinolabs/xrdp/commit/4def30ab8ea445cdc06832a44c3ec40a506a0ffa | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Neutrinolabs Search vendor "Neutrinolabs" | Xrdp Search vendor "Neutrinolabs" for product "Xrdp" | 0.9.17 Search vendor "Neutrinolabs" for product "Xrdp" and version "0.9.17" | - |
Affected
| ||||||
Neutrinolabs Search vendor "Neutrinolabs" | Xrdp Search vendor "Neutrinolabs" for product "Xrdp" | 0.9.18 Search vendor "Neutrinolabs" for product "Xrdp" and version "0.9.18" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
|