


Perceptive Security
SOC/SIEM Consultancy

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Network Infrastructure, Enterprise Applications
FreeRDP versions prior to 3.26.0 contain a heap-buffer-overflow vulnerability in the gdi_CacheToSurface function. A malicious RDP server can exploit this by sending crafted RDPGFX PDUs to clients with RDPGFX enabled. The vulnerability occurs due to improper validation of destination rectangles, where validation is performed on clamped values but the copy operation uses original cacheEntry dimensions. This can result in large out-of-bounds heap writes, potentially leading to client crashes or arbitrary code execution. The vulnerability has been patched in FreeRDP version 3.26.0.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44421
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-m6ff
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
