PT-2026-67332 · Freerdp · Freerdp

·

CVE-2026-68579

·

Published

2026-08-02

·

Updated

2026-08-02

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.30.0
Description A heap-based buffer overflow exists in the Windows clipboard client's CliprdrStream Read() function. The issue occurs when an OLE paste consumer calls IStream::Read with a fixed-size buffer of cb bytes; the CliprdrStream Read() function then copies the response from the RDP server using the server-supplied length req fsize instead of the cb value. A compromised RDP server can send an oversized CB FILECONTENTS RESPONSE, leading to an out-of-bounds write of attacker-controlled data into the paste consumer's heap buffer during a clipboard paste operation.
Recommendations Update to version 3.30.0 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68579
GHSA-M37J-JCR2-8GCC

Affected Products

Freerdp