PT-2026-67332 · Freerdp · Freerdp
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.30.0
Description
A heap-based buffer overflow exists in the Windows clipboard client's
CliprdrStream Read() function. The issue occurs when an OLE paste consumer calls IStream::Read with a fixed-size buffer of cb bytes; the CliprdrStream Read() function then copies the response from the RDP server using the server-supplied length req fsize instead of the cb value. A compromised RDP server can send an oversized CB FILECONTENTS RESPONSE, leading to an out-of-bounds write of attacker-controlled data into the paste consumer's heap buffer during a clipboard paste operation.Recommendations
Update to version 3.30.0 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp