PT-2026-25333 · Freerdp+1 · Freerdp+1
Ehdgks0627
·
Published
2026-01-01
·
Updated
2026-05-12
·
CVE-2026-29775
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.24.0
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. A client-side heap out-of-bounds read/write issue exists in FreeRDP's bitmap cache subsystem. This is due to an incorrect boundary check in the
bitmap cache put function when handling a CACHE BITMAP ORDER (Rev1) message with a cacheId equal to maxCells. This allows a malicious server to bypass security checks and access memory outside the allocated array.Recommendations
Update to version 3.24.0 or later.
Exploit
Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freerdp
Rocky Linux