


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STA…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 14:10:40
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
FreeRDP versions before 3.29.0 contain client-side heap use-after-free vulnerabilities in the async update message proxy. The flaws affect RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER processing when AsyncUpdate is enabled. A malicious or compromised RDP server can send crafted update orders that trigger the vulnerability. The message proxy performs shallow copies of structures containing nested parser-owned pointers such as titleInfo.string, windowRects, visibilityRects, and icon buffers. After the callback returns, the parser frees those nested buffers, leaving the queued async message with stale dangling pointers. When the async message is later dispatched, it accesses freed memory, potentially leading to memory corruption or a client crash. The fix is available in FreeRDP 3.29.0 and is documented in a GitHub security advisory and commit.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67300
https://github.com/FreeRDP/FreeRDP/commit/5370fb26fbf034ecd11d3026b6ad639b5fff493f
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-33gg-h66j-3697
https://www.vulncheck.com/advisories/freerdp-before-use-after-free-via-async-message-proxy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
