PT-2026-67281 · Freerdp · Freerdp

CVE-2026-67301

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description An out-of-bounds read exists in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When the AsyncUpdate feature is enabled, the functions update message PolygonSC() and update message PolygonCB() allocate a new points array but incorrectly copy point data from the address of the order structure rather than from polygonSC->points or polygonCB->points. This flaw allows a malicious or compromised RDP server to send crafted PolygonSC or PolygonCB update orders, potentially leading to client-side memory disclosure or a client crash.
Recommendations Update FreeRDP to version 3.29.0 or later. As a temporary mitigation, avoid using the /async-update flag when running xfreerdp.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67301
GHSA-VXP3-7G6Q-RQ2W

Affected Products

Freerdp