top of page
perceptive_background_267k.jpg

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STA…

Published:

31 juli 2026 om 22:00:00

Alert date:

1 augustus 2026 om 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Zero-Day Vulnerabilities

FreeRDP versions before 3.29.0 contain client-side heap use-after-free vulnerabilities in the async update message proxy. The flaws affect RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER processing when AsyncUpdate is enabled. A malicious or compromised RDP server can send crafted update orders that trigger the vulnerability. The message proxy performs shallow copies of structures containing nested parser-owned pointers such as titleInfo.string, windowRects, visibilityRects, and icon buffers. After the callback returns, the parser frees those nested buffers, leaving the queued async message with stale dangling pointers. When the async message is later dispatched, it accesses freed memory, potentially leading to memory corruption or a client crash. The fix is available in FreeRDP 3.29.0 and is documented in a GitHub security advisory and commit.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page