PT-2026-70898 · Freerdp · Freerdp
CVE-2026-73242
·
Published
2026-07-26
·
Updated
2026-08-31
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.30.0
Description
The
kerberos DecryptMessage() function in the winpr/libwinpr/sspi/Kerberos/kerberos.c file fails to properly bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets. This heap buffer overflow allows a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption, which could lead to the disclosure of protected information or a denial of service.Recommendations
Update to version 3.30.0.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp