PT-2026-70158 · Freerdp · Freerdp

·

CVE-2026-72745

·

Published

2026-07-26

·

Updated

2026-08-13

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.30.0
Description A heap-based out-of-bounds vulnerability exists in the kerberos DecryptMessage() function within the winpr/libwinpr/sspi/Kerberos/kerberos.c file. The issue occurs because the 16-bit EC (extra count) field of a peer-supplied GSS Wrap token is used in pointer arithmetic to locate encrypted regions without proper bounds checking. A malicious peer can provide a large EC value during CredSSP/NLA authentication, causing the decryption operation's base pointers to move beyond the end of the token buffer. Since AES-CTS-HMAC enctypes perform decryption in place before the HMAC integrity check, this leads to out-of-bounds read and write operations, which may result in information disclosure, memory corruption, or denial of service.
Recommendations Update to version 3.30.0 or later.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11521
CVE-2026-72745
GHSA-VV64-95PC-VJ9V

Affected Products

Freerdp