cvedb.io
CVE-2022-24883
HIGH · CVSS 7.4
EPSS exploitation probability: 0%
Published 2022-04-26T16:15:47.883 · Last modified 2026-06-17T04:32:43.533

Summary

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.

Affected products

freerdp — freerdp

Does this affect you?

Add your gear to cvedb and we'll alert you only when freerdp ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.