Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-41160 — FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of CVE project by @Sn0wAlice | Kitploit
Tools/GitHubGitHub/jajangjaman/cve-2021-41160
Memory ForensicsVulnerability AnalysisExploitationBinary AnalysisLearning & EducationRemote Access Tool
GitHubjajangjaman/cve-2021-41160

CVE-2021-41160

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of CVE project by @Sn0wAlice

43 years agoNot yet reviewed
Share

CVE-2021-41160

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send 0 width/height or out of bound rectangles to trigger out of bound writes. With 0 width or heigth the memory allocation will be 0 but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.

authenticationcomplexityvector
NONEMEDIUMNETWORK
confidentialityintegrityavailability
PARTIALPARTIALPARTIAL

CVSS Score: 6.8

References

  • https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7c9r-6r2q-93qg

  • https://lists.fedoraproject.org/archives/list/[email protected]/message/DWJXQOWKNR7O5HM2HFJOM4GBUFPTE3RG/

  • https://lists.fedoraproject.org/archives/list/[email protected]/message/ZXCR73EDVPLI6TRWRAWJCJ7OBYDKBB74/

  • https://lists.fedoraproject.org/archives/list/[email protected]/message/WIZUPVRGCWUDAPDOQVUGUIYUO7UWKMXX/

  • https://security.gentoo.org/glsa/202210-24

Brut File

  • CVE-2021-41160.json

About this repository

This repository is part of the project Live Hack CVE. Made by Sn0wAlice for the people that care about security and need to have a feed of the latest CVEs. Hope you enjoy it, don't forget to star the repo and follow me on Twitter and Github

Download Tool