top of page
perceptive_background_267k.jpg

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When…

Published:

31 July 2026 at 22:00:00

Alert date:

1 August 2026 at 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications

FreeRDP versions before 3.29.0 are affected by out-of-bounds read vulnerabilities in the async update message proxy for PolygonSC and PolygonCB primary drawing orders. The flaw occurs when AsyncUpdate is enabled, causing update_message_PolygonSC() and update_message_PolygonCB() to copy point data from the wrong memory address. Instead of reading from polygonSC->points or polygonCB->points, data is copied from the address of the order structure itself. A malicious or compromised RDP server can exploit this by sending crafted PolygonSC/PolygonCB update orders to the client. The impact includes potential memory disclosure and client-side crashes. The vulnerability is client-side, requiring the client to connect to a malicious RDP server with AsyncUpdate enabled. A fix is available in FreeRDP 3.29.0, with the patch referenced in the official GitHub commit.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page