Improper handling of exceptional conditions in Suricata - #VU152927
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to limit RDP visibility.
The vulnerability exists due to improper handling of exceptional conditions in the RDP application-layer parser when processing a crafted MCS/CS message. A remote attacker can send a crafted MCS/CS message to cause RDP parsing in one direction of an affected flow to stop making progress.
Later RDP transactions in the affected direction are not decoded or logged, while raw stream inspection and packet-processing threads remain active.