CVE-2026-67290

FreeRDP · FreeRDP

An out-of-bounds read vulnerability exists in FreeRDP before version 3.29.0, which can be triggered via the TSMF (Transport Stream Multimedia Framework) component.

Executive summary

A heap out-of-bounds read vulnerability in FreeRDP allows an unauthenticated attacker to cause a denial of service through specially crafted TSMF multimedia traffic.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) located within the TSMF implementation. An unauthenticated attacker can trigger this condition by sending malicious network packets, leading to process instability.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high risk of service interruption. A crash caused by an out-of-bounds read can lead to loss of availability for remote sessions, potentially impacting user productivity and administrative workflows.

Remediation

Immediate Action: Apply the security update by upgrading to FreeRDP version 3.29.0 or higher.

Proactive Monitoring: Review security logs for anomalous TSMF protocol traffic or frequent service crashes that might indicate an attempt to trigger the vulnerability.

Compensating Controls: Implement network segmentation to isolate systems running FreeRDP and apply WAF or IPS rules to filter suspicious multimedia-related traffic.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for service denial, it is critical to upgrade to the patched version as soon as possible. Organizations should treat this update as a high priority for any infrastructure relying on FreeRDP for remote connectivity.