PT-2025-27581 · Apache+2 · Apache Guacamole+2

·

CVE-2024-35164

·

Published

2025-07-01

·

Updated

2025-12-16

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache Guacamole versions 1.5.5 and older
Description: The issue is related to improper validation of console codes received from servers via text-based protocols like SSH. A malicious user with access to a text-based connection could execute arbitrary code with the privileges of the running guacd process by sending a specially-crafted sequence of console codes.
Recommendations: For Apache Guacamole versions 1.5.5 and older, upgrade to version 1.6.0 to fix the issue.

Exploit

Fix

DoS

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16097
CVE-2024-35164

Affected Products

Alt Linux
Apache Guacamole
Red Os