top of page
perceptive_background_267k.jpg

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before strea…

Published:

31 juli 2026 om 22:00:00

Alert date:

1 augustus 2026 om 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Security Tools

FreeRDP versions before 3.29.0 contain a denial of service vulnerability in the RDPEI server channel handler. The handler fails to validate the maximum PDU body length prior to stream allocation. A malicious RDP client can exploit this by sending a header-only RDPEI message with an inflated declared body length. This causes the server to allocate excessive memory, potentially leading to resource exhaustion and denial of service. The vulnerability resides in the server-side component, meaning it can be triggered remotely by any connecting RDP client. A fix is available in FreeRDP 3.29.0. Users and system administrators running FreeRDP as an RDP server should upgrade immediately to mitigate the risk.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page