Back to Database
Status published
High
CVE-2020-11039
Integer Overflow in FreeRDP
Vulnerability Description
In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-11039
Credits & Attribution
No credits recorded in the NVD database.
References
More from FreeRDP
View All →CVE-2025-68118
Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage
Medium
6.6
CVE-2024-32662
FreeRDP rdp_redirection_read_base64_wchar out of bound read
High
7.5
CVE-2024-32661
FreeRDP rdp_write_logon_info_v1 NULL access
High
7.5
CVE-2024-32660
FreeRDP zgfx_decompress out of memory vulnerability
High
7.5
CVE-2024-32659
freerdp_image_copy out of bound read
Critical
9.8
Affected Vendor
FreeRDP
View all reports →Affected Software
FreeRDP
Vulnerable Versions:
<= 2.0.0
Timeline
Official Publish:
May 29th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N