PT-2026-67273 · Freerdp · Freerdp
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
An improper certificate hostname validation issue exists where the TLS hostname matcher
tls match hostname() in libfreerdp/crypto/tls.c incorrectly handles wildcard patterns. Specifically, a pattern like *.example.com is treated as matching any hostname ending in .example.com, allowing wildcard certificates to be accepted for multi-label subdomains such as a.b.example.com. This behavior weakens TLS server authentication.Recommendations
Update FreeRDP to version 3.29.0 or later.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp