


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfree…
Published:
1 August 2026 at 00:00:00
Alert date:
1 August 2026 at 16:10:40
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
FreeRDP versions before 3.29.0 contain a client-side heap use-after-free vulnerability in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled. The flaw exists in update_message_WindowIcon() where a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with a parser-owned pointer. After the parser callback returns, the original iconInfo is freed, but the queued async message retains and later dispatches the stale pointer. A malicious or compromised RDP server can exploit this by sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON. Successful exploitation leads to memory corruption and client crash. The vulnerability is triggered only when the /async-update flag is used (e.g., xfreerdp /async-update). A fix has been committed to the FreeRDP GitHub repository and is included in version 3.29.0.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67299
https://github.com/FreeRDP/FreeRDP/commit/5370fb26fbf034ecd11d3026b6ad639b5fff493f
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-34hq-hwjw-q8v3
https://www.vulncheck.com/advisories/freerdp-before-use-after-free-via-windowicon-async-message
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
