PT-2026-67264 · Freerdp · Freerdp
CVSS v4.0
2.4
Low
| Vector | AV:P/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
An out-of-bounds heap read occurs in the UVC H.264 extension-unit parser when the system fails to validate the descriptor length before accessing the GUID field. A local attacker using a malicious USB video camera can trigger this read beyond allocated bounds during camera stream setup, resulting in a denial of service.
Recommendations
Update to version 3.29.0 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp