CVE-2026-33982
7.1FreeRDP · FreeRDP
FreeRDP versions prior to 3.24.2 contain a heap-buffer-overflow read vulnerability in winpr_aligned_offset_recalloc that can lead to information disclosure or system instability.
Executive summary
A heap-based out-of-bounds read vulnerability in FreeRDP prior to version 3.24.2 poses a significant risk of unauthorized information disclosure and service disruption.
Vulnerability
This is a heap-buffer-overflow read vulnerability (CWE-125) occurring in the winpr_aligned_offset_recalloc function. An unauthenticated attacker may trigger this condition through a specially crafted request, potentially leading to unauthorized memory access.
Business impact
The exploitation of this flaw could result in the disclosure of sensitive memory contents or cause the application to crash, leading to service downtime. With a CVSS score of 7.1, this is classified as a High severity vulnerability that could impact the integrity and availability of systems relying on FreeRDP for remote access. Organizations should prioritize remediation to prevent potential data leakage or operational disruption.
Remediation
Immediate Action: Update all FreeRDP installations to version 3.24.2 or later to remediate the heap-buffer-overflow flaw.
Proactive Monitoring: Monitor system logs for repeated application crashes or unusual memory usage patterns that may indicate attempts to trigger this buffer overflow.
Compensating Controls: Restrict access to RDP services to trusted networks only and implement endpoint protection solutions to detect anomalous process behavior.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
Given the High severity of this vulnerability, immediate patching is required to ensure the continued security of remote access infrastructure. Administrators should verify their current versions of FreeRDP and apply the 3.24.2 update across all affected environments as soon as possible to mitigate the risk of memory-related exploits.