PT-2026-67268 · Freerdp · Freerdp
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
A null pointer dereference occurs in smartcard cache request decoders when they accept NULL NDR pointers for
LookupName during SCARD IOCTL READCACHEA and SCARD IOCTL WRITECACHEA operations. If smartcard emulation is enabled, an attacker can send crafted smartcard cache requests with NULL lookup-name pointers to trigger the strlen() function on a null pointer, leading to the termination of the client process.Recommendations
Update to version 3.29.0 or later.
Disable smartcard emulation to mitigate the risk of exploitation.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp