#VU80401 Integer overflow in FreeRDP - CVE-2023-40186
Published: September 4, 2023
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the gdi_CreateSurface() function in libfreerdp/gdi/gfx.c. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.