CVE-2026-67291

FreeRDP · FreeRDP

An out-of-bounds read vulnerability exists in FreeRDP before version 3.29.0, specifically within the glyph fragment addition functionality.

Executive summary

An unauthenticated remote attacker can trigger a denial of service in FreeRDP by exploiting a heap out-of-bounds read vulnerability during glyph fragment processing.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) occurring during the processing of glyph fragments. The vulnerability is accessible to unauthenticated attackers over the network.

Business impact

With a CVSS score of 7.5, this vulnerability presents a significant risk to the availability of systems using FreeRDP. Exploitation causes the application to crash, resulting in service downtime that may affect critical business operations and remote access capabilities.

Remediation

Immediate Action: Upgrade to FreeRDP version 3.29.0 or later to resolve the memory safety issue.

Proactive Monitoring: Monitor for unexpected service terminations or memory-related errors in application logs that could suggest exploit attempts.

Compensating Controls: Utilize intrusion prevention systems to detect and block malformed glyph fragment data packets being sent to the RDP service.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability poses a clear risk to system availability and should be addressed promptly. Organizations are advised to plan and execute an update to version 3.29.0 as part of their standard security maintenance cycle to mitigate this risk.