PT-2026-67280 · Freerdp · Freerdp
CVE-2026-67300
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
A client-side heap use-after-free issue exists in the async update message proxy for RAIL WINDOW STATE ORDER and NOTIFY ICON STATE ORDER when AsyncUpdate is enabled. A malicious or compromised RDP server can send crafted update orders causing the message proxy to shallow-copy structures containing nested parser-owned pointers, such as
titleInfo.string, windowRects, visibilityRects, and icon buffers. Because the parser frees these nested buffers after the callback returns, the queued async message dispatches stale pointers, which can lead to memory corruption or a client crash.Recommendations
Update to version 3.29.0 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp