PT-2026-70158 · Freerdp · Freerdp
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.30.0
Description
A heap-based out-of-bounds vulnerability exists in the
kerberos DecryptMessage() function within the winpr/libwinpr/sspi/Kerberos/kerberos.c file. The issue occurs because the 16-bit EC (extra count) field of a peer-supplied GSS Wrap token is used in pointer arithmetic to locate encrypted regions without proper bounds checking. A malicious peer can provide a large EC value during CredSSP/NLA authentication, causing the decryption operation's base pointers to move beyond the end of the token buffer. Since AES-CTS-HMAC enctypes perform decryption in place before the HMAC integrity check, this leads to out-of-bounds read and write operations, which may result in information disclosure, memory corruption, or denial of service.Recommendations
Update to version 3.30.0 or later.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp