Impact
The flaw is a heap‑based buffer overflow in the RDP protocol dissector of Wireshark. When the application processes malicious RDP packets, it crashes rather than executing arbitrary code. The result is a denial of service that impacts only the running Wireshark process and does not provide an attacker with elevated privileges or data exfiltration capabilities.
Affected Systems
Wireshark Foundation’s Wireshark application is affected. Versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are vulnerable; all newer releases are not exposed to this flaw.
Risk and Exploitability
The CVSS score of 3.1 indicates a low impact severity, and the vulnerability is not listed in CISA’s KEV database. Exploitation requires Wireshark to parse crafted RDP data, which can occur when a user opens a malicious capture file or when the application is capturing live traffic that contains such packets. The EPSS score of 0.00174 indicates a very low exploitation probability, and the low CVSS suggests that the likelihood of exploitation is minimal, though a local or managed network attacker could still cause a crash for a user running Wireshark.
OpenCVE Enrichment
Debian DSA