VYPR
Unrated severityOSV Advisory· Published Jul 2, 2020· Updated Aug 4, 2024

CVE-2020-9497

CVE-2020-9497

Description

Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Invalid data validation in Apache Guacamole 1.1.0 and older allows information disclosure via malicious RDP server static virtual channel PDUs.

Vulnerability

Apache Guacamole versions 1.1.0 and older do not properly validate data received from RDP servers through static virtual channels. When a user connects to a malicious or compromised RDP server, specially crafted Protocol Data Units (PDUs) can trigger memory disclosure in the guacd process handling the connection [1]. The vulnerability resides in the RDP protocol handling code and requires no special configuration beyond a standard Guacamole deployment [1].

Exploitation

An attacker must first compromise an RDP server that a Guacamole user will connect to [1]. The attacker then sends malicious static virtual channel PDUs to the connecting Guacamole gateway [1]. No authentication bypass or prior access to the gateway is required; the exploit is triggered automatically during the normal RDP session setup and data exchange [1]. The attack does not require user interaction beyond the user initiating a connection to the target RDP server [1].

Impact

Successful exploitation results in disclosure of information from the memory of the guacd process [1]. The disclosed memory may contain sensitive data from other connected Guacamole sessions, including credentials or session content [1]. Under certain conditions, this memory leak could be chained with other vulnerabilities to achieve remote code execution on the gateway server [1].

Mitigation

Apache Guacamole 1.2.0 and later contain the fix for this vulnerability [1]. Users and administrators should upgrade to version 1.2.0 or later [1]. As of July 2020, no workaround is available for versions 1.1.0 and older [1]. Fedora package announcements provide updates but the referenced pages are inaccessible due to bot protection [2][3].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.