PT-2026-92072 · Freerdp+1 · Freerdp+1
CVE-2026-91953
·
Published
2026-09-15
·
Updated
2026-09-24
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.31.0
Description
A heap buffer overflow occurs in the
nego send negotiation request() function due to a failure to validate the length of the LB LOAD BALANCE INFO field before writing it to a fixed 512-byte buffer. A malicious RDP server or a man-in-the-middle attacker can send a Server Redirection PDU containing an oversized LB LOAD BALANCE INFO value to overflow the buffer with controlled content. This can lead to heap corruption or a denial of service before the authentication process is completed.Recommendations
Update to version 3.31.0 or later.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Ubuntu