PT-2026-29133 · Freerdp+3 · Freerdp+3

·

CVE-2026-33952

·

Published

2026-01-01

·

Updated

2026-08-10

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.24.2
Description FreeRDP is a free implementation of the Remote Desktop Protocol. An unvalidated auth length field read from the network triggers a WINPR ASSERT() failure in the rts read auth verifier no checks() function, causing FreeRDP clients connecting through a malicious RDP Gateway to crash. This is a pre-authentication denial of service affecting clients using RPC-over-HTTP gateway transport. The assertion is active in default release builds.
Recommendations Update to version 3.24.2 or later.

Exploit

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04667
CVE-2026-33952
GHSA-4V4P-9V5X-HC93
OPENSUSE-SU-2026:10633-1
OPENSUSE-SU-2026:20657-1
SUSE-SU-2026:21436-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu