top of page
perceptive_background_267k.jpg

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient…

Published:

31 July 2026 at 22:00:00

Alert date:

1 August 2026 at 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications

FreeRDP versions before 3.29.0 are affected by a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder. The flaw occurs when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can exploit this by sending malformed media format data from a server to a vulnerable client. The vulnerability arises from reading fixed offsets without validating the source buffer length, which can trigger a crash. This is a server-to-client attack vector, meaning a malicious or compromised RDP server could exploit connecting clients. The vulnerability has been patched in FreeRDP 3.29.0. A corresponding GitHub commit and security advisory (GHSA-whq8-c3v3-p8v8) have been published. The issue is also documented by VulnCheck. Users and administrators should upgrade FreeRDP to version 3.29.0 or later to mitigate the risk.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page