CVE Vulnerabilities

CVE-2024-32661

NULL Pointer Dereference

Published: Apr 23, 2024 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible NULL access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FreerdpFreerdp*3.5.1 (excluding)
Red Hat Enterprise Linux 9RedHatfreerdp-2:2.11.7-1.el9*
Freerdp2Ubuntuesm-apps/noble*
Freerdp2Ubuntuesm-infra/focal*
Freerdp2Ubuntufocal*
Freerdp2Ubuntujammy*
Freerdp2Ubuntumantic*
Freerdp2Ubuntunoble*
Freerdp2Ubuntuoracular*
Freerdp2Ubuntuplucky*
Freerdp3Ubuntudevel*
Freerdp3Ubuntunoble*
Freerdp3Ubuntuoracular*
Freerdp3Ubuntuplucky*
Freerdp3Ubuntuquesting*
Freerdp3Ubuntuupstream*

Potential Mitigations

References