WRITEUP

WRITEUP
Exploit for CVE-2018-8787 - FreeRDP <2.0.0-rc4 - Memory Corruption
AI Analysis

This patch addresses CVE-2018-8787 in FreeRDP by adding bounds checking to prevent integer overflow in the `gdi_Bitmap_Decompress` function. The fix ensures that calculations for bitmap dimensions and pixel format do not exceed `UINT32_MAX`, mitigating potential denial-of-service or memory corruption vulnerabilities.

Attack Type
DoS
Complexity
trivial
Reliability
reliable
MITRE ATT&CK
T1499 - Endpoint Denial of Service
Loading exploit code...
Download ZIP Password: eip
Authors
Armin Novak
Vulnerability
CVE-2018-8787
FreeRDP <2.0.0-rc4 - Memory Corruption
CRITICAL
CVSS 9.8