Cyber Posture

CVE-2022-1736

Critical

Published: 31 January 2025

Published
31 January 2025
Modified
26 August 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0054 67.6th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

Security Summary

CVE-2022-1736 is a vulnerability in Ubuntu's configuration of gnome-control-center that allowed Remote Desktop Sharing to be enabled by default. This issue affects Ubuntu systems using the gnome-control-center component, with related involvement from gnome-remote-desktop, as documented in the associated Launchpad bug report.

The vulnerability carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), enabling remote exploitation over the network by unauthenticated attackers with low attack complexity and no user interaction. Attackers can achieve high impacts on confidentiality, integrity, and availability, potentially gaining unauthorized remote access to the desktop session due to the default-enabled sharing feature.

Ubuntu security advisories provide mitigation details, including patches in USN-5430-1. Additional information on fixes and affected versions is available at https://ubuntu.com/security/CVE-2022-1736 and https://ubuntu.com/security/notices/USN-5430-1, along with the bug tracker at https://bugs.launchpad.net/ubuntu/+source/gnome-remote-desktop/+bug/1973028.

Details

CWE(s)
NVD-CWE-noinfo

Affected Products

gnome
gnome-remote-desktop
42.1.1, 42.1.1-1, 42.1.1-2
canonical
ubuntu linux
18.04, 20.04, 22.04

References