Skip to main content

CVE-2024-32040

8.1
HIGHCVSS v3.1 Base Score
1.00%
LOW RiskEPSS (77th percentile)

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use `-nsc`).

Published: 4/22/2024
Modified: 11/3/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

1.00%LOW Exploitation Risk
77th percentile

This vulnerability has a 1.00% probability of being exploited in the next 30 days, ranking higher than 77% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-191)

CVE-2025-29912CRITICAL 9.8

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer underflow in the `Crypto_TC_ProcessSecurity` function of CryptoLib leads to a heap buffer overflow. The vulnerability is triggered when the `fl` (frame length) field in a Telecommand (TC) packet is set to 0. This underflow causes the frame length to be interpreted as 65535, resulting in out-of-bounds memory access. This critical vulnerability can be exploited to cause a denial of service (DoS) or potentially achieve remote code execution. Users of CryptoLib are advised to apply the recommended patch or avoid processing untrusted TC packets until a fix is available.

3/17/2025
CVE-2024-10838CRITICAL 9.1

An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.

3/12/2025
CVE-2018-9388CRITICAL 9.8

In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.

12/5/2024
CVE-2024-38063CRITICAL 9.8

Windows TCP/IP Remote Code Execution Vulnerability

8/13/2024
CVE-2024-0808CRITICAL 9.8

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

1/24/2024

Similar SeverityHIGH