CVE-2026-67291
FreeRDP · FreeRDP
An out-of-bounds read vulnerability exists in FreeRDP before version 3.29.0, specifically within the glyph fragment addition functionality.
Executive summary
An unauthenticated remote attacker can trigger a denial of service in FreeRDP by exploiting a heap out-of-bounds read vulnerability during glyph fragment processing.
Vulnerability
This is an out-of-bounds read vulnerability (CWE-125) occurring during the processing of glyph fragments. The vulnerability is accessible to unauthenticated attackers over the network.
Business impact
With a CVSS score of 7.5, this vulnerability presents a significant risk to the availability of systems using FreeRDP. Exploitation causes the application to crash, resulting in service downtime that may affect critical business operations and remote access capabilities.
Remediation
Immediate Action: Upgrade to FreeRDP version 3.29.0 or later to resolve the memory safety issue.
Proactive Monitoring: Monitor for unexpected service terminations or memory-related errors in application logs that could suggest exploit attempts.
Compensating Controls: Utilize intrusion prevention systems to detect and block malformed glyph fragment data packets being sent to the RDP service.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability poses a clear risk to system availability and should be addressed promptly. Organizations are advised to plan and execute an update to version 3.29.0 as part of their standard security maintenance cycle to mitigate this risk.