top of page
perceptive_background_267k.jpg

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's s…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Security Tools

A heap-buffer-overflow vulnerability exists in FreeRDP versions prior to 3.26.0. A malicious RDP client can trigger this vulnerability by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength to the server-side clipboard channel. This vulnerability can crash the server process causing remote denial of service and may potentially allow code execution due to heap memory corruption. The issue affects the cliprdr channel implementation and has been fixed in version 3.26.0.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page