CVE-2022-23493
Last modified
CVE-2022-23493 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Neutrinolabs | Xrdp | < 0.9.21 |
| Debian | Debian Linux | 11.0 |
References
- https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-59wp-3wq6-jh5vThird Party Advisory
- https://www.debian.org/security/2023/dsa-5502Third Party Advisory
- https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-59wp-3wq6-jh5vThird Party Advisory
- https://www.debian.org/security/2023/dsa-5502Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23493?
How severe is CVE-2022-23493?
How do I fix CVE-2022-23493?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23487js-libp2p is the official javascript Implementation of libp2…7.5
- CVE-2022-23488BigBlueButton is an open source web conferencing system. Ver…7.5
- CVE-2022-2349Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-23490BigBlueButton is an open source web conferencing system. Ver…4.3
- CVE-2022-23491Certifi is a curated collection of Root Certificates for val…7.5
- CVE-2022-23492go-libp2p is the offical libp2p implementation in the Go pro…7.5
- CVE-2022-23494tinymce is an open source rich text editor. A cross-site scr…6.1
- CVE-2022-23495go-merkledag implements the 'DAGService' interface and adds …7.5
- CVE-2022-23496 Yet Another UserAgent Analyzer (Yauaa) is a java library th…7.5
- CVE-2022-23497FreshRSS is a free, self-hostable RSS aggregator. User confi…7.5
- CVE-2022-23498Grafana is an open-source platform for monitoring and observ…8.8
- CVE-2022-23499HTML sanitizer is written in PHP, aiming to provide XSS-safe…6.1
Are you affected by CVE-2022-23493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
