CVE-2020-13398

HIGH

FreeRDP < 2.1.1 - Out-of-bounds Write in crypto_rsa_common

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-13398. PoCs published by SpiralBL0CK.

AI-analyzed exploit summary This PoC exploits CVE-2020-13398 by crafting a fake RDP license packet with a malformed RSA modulus and exponent, causing a crash in FreeRDP clients. It simulates an RDP server to trigger the vulnerability during the licensing phase.

Description

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

Exploits (1)

nomisec WORKING POC 1 stars
by SpiralBL0CK · poc
https://github.com/SpiralBL0CK/PoC-crash-CVE-2020-13398-

This PoC exploits CVE-2020-13398 by crafting a fake RDP license packet with a malformed RSA modulus and exponent, causing a crash in FreeRDP clients. It simulates an RDP server to trigger the vulnerability during the licensing phase.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: FreeRDP (versions prior to 2.1.2)
No auth needed
Prerequisites: Network access to target · Target initiates RDP connection to attacker-controlled server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.3
EPSS 0.0239
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Details

CWE
CWE-787
Status published
Products (8)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.10
canonical/ubuntu_linux 20.04
debian/debian_linux 9.0
debian/debian_linux 10.0
freerdp/freerdp < 2.1.1
opensuse/leap 15.1
Published May 22, 2020
Tracked Since Feb 18, 2026