


Perceptive Security
SOC/SIEM Consultancy

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's s…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Network Infrastructure, Security Tools
A heap-buffer-overflow vulnerability exists in FreeRDP versions prior to 3.26.0. A malicious RDP client can trigger this vulnerability by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength to the server-side clipboard channel. This vulnerability can crash the server process causing remote denial of service and may potentially allow code execution due to heap memory corruption. The issue affects the cliprdr channel implementation and has been fixed in version 3.26.0.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44420
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mvpx-xj7r-3p3r
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
