Improper handling of exceptional conditions in Suricata - #VU152927

 

Improper handling of exceptional conditions in Suricata - #VU152927

Published: September 30, 2026


Vulnerability identifier: #VU152927
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to limit RDP visibility.

The vulnerability exists due to improper handling of exceptional conditions in the RDP application-layer parser when processing a crafted MCS/CS message. A remote attacker can send a crafted MCS/CS message to cause RDP parsing in one direction of an affected flow to stop making progress.

Later RDP transactions in the affected direction are not decoded or logged, while raw stream inspection and packet-processing threads remain active.


Affected software

Suricata

Remediation

Install security update from vendor's website.

Suricata - update to 8.0.7

External References

Related Security Bulletins