#VU28200 Out-of-bounds read in FreeRDP - CVE-2020-13396
Published: May 25, 2020
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. A remote attacker can trigger out-of-bounds read error via a specially crafted authentication message and read contents of memory on the system.