Freerdp · Freerdp · CVE-2026-67305
**Name of the Vulnerable Software and Affected Versions**
FreeRDP Windows client versions prior to 3.29.0
**Description**
A heap buffer overflow occurs in the clipboard virtual channel when processing `CLIPRDR FILE CONTENTS RESPONSE` PDUs (Protocol Data Units) because the server-provided size is not validated against the destination buffer. A malicious RDP server can send a response with a data payload larger than requested, leading to arbitrary heap memory corruption. This may enable remote code execution when a user performs a paste operation.
**Recommendations**
Update FreeRDP Windows client to version 3.29.0 or later.