CVE-2020-13398
HIGHFreeRDP < 2.1.1 - Out-of-bounds Write in crypto_rsa_common
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-13398. PoCs published by SpiralBL0CK.
AI-analyzed exploit summary This PoC exploits CVE-2020-13398 by crafting a fake RDP license packet with a malformed RSA modulus and exponent, causing a crash in FreeRDP clients. It simulates an RDP server to trigger the vulnerability during the licensing phase.
Description
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
Exploits (1)
This PoC exploits CVE-2020-13398 by crafting a fake RDP license packet with a malformed RSA modulus and exponent, causing a crash in FreeRDP clients. It simulates an RDP server to trigger the vulnerability during the licensing phase.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L