Information disclosure in FreeRDP - CVE-2018-1000852
Published: January 29, 2019
FreeRDP
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request. A remote attacker can connect the rdp server with echo option and gain unauthorized access to sensitive information on the system.