PT-2026-67280 · Freerdp · Freerdp

CVE-2026-67300

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description A client-side heap use-after-free issue exists in the async update message proxy for RAIL WINDOW STATE ORDER and NOTIFY ICON STATE ORDER when AsyncUpdate is enabled. A malicious or compromised RDP server can send crafted update orders causing the message proxy to shallow-copy structures containing nested parser-owned pointers, such as titleInfo.string, windowRects, visibilityRects, and icon buffers. Because the parser frees these nested buffers after the callback returns, the queued async message dispatches stale pointers, which can lead to memory corruption or a client crash.
Recommendations Update to version 3.29.0 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67300
GHSA-33GG-H66J-3697

Affected Products

Freerdp