CVE-2026-67288
FreeRDP · FreeRDP
A NULL pointer dereference vulnerability exists in FreeRDP before version 3.29.0, which can be triggered via specially crafted smartcard cache data.
Executive summary
An unauthenticated remote attacker can cause a denial of service in FreeRDP by exploiting a NULL pointer dereference flaw in smartcard cache processing.
Vulnerability
This is a NULL pointer dereference vulnerability (CWE-476) occurring within the smartcard cache component. The attack vector is network-based and requires no authentication or user interaction to reach the vulnerable code path.
Business impact
Successful exploitation of this vulnerability results in a denial of service, causing the FreeRDP application to crash. Given the CVSS score of 7.5, this represents a high-severity risk to business continuity, as it can disrupt remote desktop sessions and administrative access dependent on this protocol implementation.
Remediation
Immediate Action: Update FreeRDP to version 3.29.0 or later to incorporate the necessary security fixes.
Proactive Monitoring: Monitor system logs for unexpected application crashes or service restarts associated with the FreeRDP process.
Compensating Controls: Utilize network-level access controls to restrict access to RDP services to trusted IP addresses only, reducing the exposure to potential attackers.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high severity of this vulnerability necessitates immediate attention to prevent service disruption. Administrators should prioritize updating all instances of FreeRDP to version 3.29.0 to eliminate the risk of denial of service attacks.