


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient…
Published:
31 July 2026 at 22:00:00
Alert date:
1 August 2026 at 14:10:40
Source:
nvd.nist.gov
Network Infrastructure, Enterprise Applications
FreeRDP versions before 3.29.0 are affected by a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder. The flaw occurs when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can exploit this by sending malformed media format data from a server to a vulnerable client. The vulnerability arises from reading fixed offsets without validating the source buffer length, which can trigger a crash. This is a server-to-client attack vector, meaning a malicious or compromised RDP server could exploit connecting clients. The vulnerability has been patched in FreeRDP 3.29.0. A corresponding GitHub commit and security advisory (GHSA-whq8-c3v3-p8v8) have been published. The issue is also documented by VulnCheck. Users and administrators should upgrade FreeRDP to version 3.29.0 or later to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67290
https://github.com/FreeRDP/FreeRDP/commit/8d3b86022f0d71aefa7bd2e466d2d391693a41b3
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-whq8-c3v3-p8v8
https://www.vulncheck.com/advisories/freerdp-before-heap-out-of-bounds-read-via-tsmf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
