PT-2026-22003 · Freerdp+3 · Freerdp+3
Pavelkohout396
·
Published
2026-01-01
·
Updated
2026-06-09
·
CVE-2026-25941
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 2.11.8
FreeRDP versions prior to 3.23.0
Description
FreeRDP, a free implementation of the Remote Desktop Protocol, contains an out-of-bounds read issue in the FreeRDP client’s RDPGFX channel. A malicious RDP server can exploit this by sending a crafted WIRE TO SURFACE 2 Protocol Data Unit (PDU) with a
bitmapDataLength value exceeding the actual data within the packet. This can result in information disclosure or client crashes when a user connects to a malicious server. The vulnerability occurs when reading uninitialized heap memory.Recommendations
Update to FreeRDP version 2.11.8 or later.
Update to FreeRDP version 3.23.0 or later.
Exploit
Fix
DoS
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freerdp
Linuxmint
Red Os
Ubuntu