PT-2026-92067 · Freerdp+1 · Freerdp+1
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.31.0
Description
An out-of-bounds write issue exists in server-side static virtual channel handling when
CHANNEL OPTION SHOW PROTOCOL is enabled. Authenticated clients can queue oversized channel messages, leading to a buffer underflow that corrupts heap memory and live pointers, which may allow for remote code execution.Recommendations
Update to version 3.31.0 or later.
Disable the
CHANNEL OPTION SHOW PROTOCOL option to mitigate the risk.Exploit
Fix
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Ubuntu