High severity7.4NVD Advisory· Published Apr 26, 2022· Updated Jun 17, 2026
CVE-2022-24883
CVE-2022-24883
Description
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a SAM file might be successful for invalid credentials if the server has configured an invalid SAM file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a SAM file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via HashCallback and/or ensure the SAM database path configured is valid and the application has file handles left.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords9 versionspkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/freerdp2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4
< 2.1.2-150200.15.15.1+ 8 more
- (no CPE)range: < 2.1.2-150200.15.15.1
- (no CPE)range: < 2.4.0-150400.3.3.1
- (no CPE)range: < 2.11.2-3.1
- (no CPE)range: < 2.1.2-150200.15.15.1
- (no CPE)range: < 2.4.0-150400.3.3.1
- (no CPE)range: < 2.1.2-12.23.1
- (no CPE)range: < 2.1.2-12.23.1
- (no CPE)range: < 2.1.2-150200.15.15.1
- (no CPE)range: < 2.4.0-150400.3.3.1
Patches
Vulnerability mechanics
References
10- github.com/FreeRDP/FreeRDP/commit/4661492e5a617199457c8074bad22f766a116cdcnvdPatchThird Party Advisory
- github.com/FreeRDP/FreeRDP/commit/6f473b273a4b6f0cb6aca32b95e22fd0de88e144nvdPatchThird Party Advisory
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qxm3-v2r6-vmwfnvdPatchThird Party Advisory
- github.com/FreeRDP/FreeRDP/releases/tag/2.7.0nvdRelease NotesThird Party Advisory
- security.gentoo.org/glsa/202210-24nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/11/msg00010.htmlnvd
- lists.debian.org/debian-lts-announce/2025/02/msg00016.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AELSWWBAM2YONRPGLWVDY6UNTLJERJYL/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOYKBQOHSRM7JQYUIYUWFOXI2JZ2J5RD/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWR6KSIKXO4B2TXBB3WH6YTNYHN46OY/nvd
News mentions
0No linked articles in our index yet.