Medium severity6.8NVD Advisory· Published Jul 2, 2025· Updated Jun 17, 2026
CVE-2024-35164
CVE-2024-35164
Description
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow arbitrary code to be executed with the privileges of the running guacd process.
Users are recommended to upgrade to version 1.6.0, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 0.8.0
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/sgs8lplbkrpvd3hrvcnnxh3028h4py70nvdMailing ListVendor Advisory
- www.openwall.com/lists/oss-security/2025/07/01/2nvd
News mentions
0No linked articles in our index yet.