PT-2026-67269 · Freerdp · Freerdp
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
Insufficient validation of CRLF and control characters occurs in the server-controlled RDP redirection
TargetNetAddress field. This value is assigned to the client's ServerHostname and is subsequently written into the proxy CONNECT request line and Host header by the http proxy connect() function without filtering when connecting through an HTTP proxy. A compromised or malicious RDP server can send a crafted redirection PDU (Protocol Data Unit) containing embedded control characters to inject arbitrary headers or requests into the HTTP proxy CONNECT request.Recommendations
Update FreeRDP to version 3.29.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp