Back to Database
Status published
Critical
CVE-2024-32459
FreeRDP Out-Of-Bounds Read in ncrush_decompress
Vulnerability Description
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-32459
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cp4q-p737-rmw9
- https://github.com/FreeRDP/FreeRDP/pull/10077
- https://github.com/FreeRDP/FreeRDP/releases/tag/2.11.6
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.5.0
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKI4UISUXYNBPN4K6TIQKDRTIJ6CDCKJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7SIS6NUNLUBOV4CPCSWKDE6T6C2W3WTR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX3U6YPZQ7PEJBVKSBUOLWVH7DHROHY5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5JL476WVJSIE7SBUKVJRVA6A52V2HOLZ/
More from FreeRDP
View All →CVE-2025-68118
Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage
Medium
6.6
CVE-2024-32662
FreeRDP rdp_redirection_read_base64_wchar out of bound read
High
7.5
CVE-2024-32661
FreeRDP rdp_write_logon_info_v1 NULL access
High
7.5
CVE-2024-32660
FreeRDP zgfx_decompress out of memory vulnerability
High
7.5
CVE-2024-32659
freerdp_image_copy out of bound read
Critical
9.8
Affected Vendor
FreeRDP
View all reports →Affected Software
FreeRDP
Vulnerable Versions:
>= 3.0.0, 3.5.0, < 2.11.6
Timeline
Official Publish:
April 22nd, 2024
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H