SB2021072810 - Information disclosure in FreeRDP
Published: July 28, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2021-37595)
The vulnerability allows a remote server to gain access to potentially sensitive information.
The vulnerability exists due to arbitrary file read vulnerability in the wfreerdp (Windows) client, if clipboard redirection is enabled (default). A malicious server can ready arbitrary file on the client's system.2) Information disclosure (CVE-ID: CVE-2021-37594)
The vulnerability allows a remote server to gain access to potentially sensitive information.
The vulnerability exists due to arbitrary file read vulnerability in the wfreerdp (Windows) client, if clipboard redirection is enabled (default). A malicious server can ready arbitrary file on the client's system.
Remediation
Install update from vendor's website.