top of page
perceptive_background_267k.jpg

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP…

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications

FreeRDP versions prior to 3.26.0 contain a heap-buffer-overflow vulnerability in the gdi_CacheToSurface function. A malicious RDP server can exploit this by sending crafted RDPGFX PDUs to clients with RDPGFX enabled. The vulnerability occurs due to improper validation of destination rectangles, where validation is performed on clamped values but the copy operation uses original cacheEntry dimensions. This can result in large out-of-bounds heap writes, potentially leading to client crashes or arbitrary code execution. The vulnerability has been patched in FreeRDP version 3.26.0.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page