Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-32459 PoC — FreeRDP Out-Of-Bounds Read in ncrush_decompress

Source
Associated Vulnerability
Title:FreeRDP Out-Of-Bounds Read in ncrush_decompress (CVE-2024-32459)
Description:FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.
Description
The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
Readme
# FreeRDP-Out-of-Bounds-Read-CVE-2024-32459-
The FreeRDP-Out-of-Bounds-Read-CVE-2024-32459 vulnerability is a security flaw discovered in FreeRDP, an open-source program used for implementing the Remote Desktop Protocol (RDP) This vulnerability arises from input processing weaknesses, allowing an attacker to send specially crafted data that leads to arbitrary code execution on the targeted system Versions of FreeRDP prior to 350 or 2116 are susceptible to out-of-bounds read Out-of-bounds read is a type of security vulnerability that occurs when a program reads data beyond the specified boundaries of an array or allocated memory This flaw enables an unauthorized remote attacker to read sensitive information from memory, potentially leading to information disclosure, data corruption, or service disruption Exploitation ...
File Snapshot

[4.0K] /data/pocs/e262633b10506158d25c226382469b30c7d3988a ├── [3.2K] FreeRDP - Out-of-Bounds Read.py └── [ 832] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →