PT-2026-67285 · Freerdp · Freerdp
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeRDP Windows client versions prior to 3.29.0
Description
A heap buffer overflow occurs in the clipboard virtual channel when processing
CLIPRDR FILE CONTENTS RESPONSE PDUs (Protocol Data Units) because the server-provided size is not validated against the destination buffer. A malicious RDP server can send a response with a data payload larger than requested, leading to arbitrary heap memory corruption. This may enable remote code execution when a user performs a paste operation.Recommendations
Update FreeRDP Windows client to version 3.29.0 or later.
Exploit
Fix
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp