PT-2026-43250 · Freerdp+1 · Freerdp+1

·

CVE-2026-40033

·

Published

2026-04-21

·

Updated

2026-07-20

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.26.0
Description A heap-buffer-overflow exists in the gdi CacheToSurface() function. This occurs because rectangle validation clamps coordinates to UINT16 MAX but copy operations use unclamped cache entry dimensions. This allows a malicious RDP server to trigger large out-of-bounds writes to heap memory, which could lead to a client crash or remote code execution.
Recommendations Update to version 3.26.0 or later.

Exploit

Fix

DoS

RCE

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36203
BDU:2026-07426
CVE-2026-40033
GHSA-P6R2-4HGM-M6FF
OPENSUSE-SU-2026:10948-1
OPENSUSE-SU-2026:21116-1
RHSA-2026:36203
SUSE-SU-2026:22194-1
USN-8561-1

Affected Products

Freerdp
Red Os