CVE-2026-67299
FreeRDP · FreeRDP
A use after free vulnerability exists in FreeRDP versions prior to 3.29.0, potentially allowing for denial of service via window icon asynchronous messages.
Executive summary
A use after free vulnerability in FreeRDP, affecting versions prior to 3.29.0, poses a significant risk of service disruption.
Vulnerability
This vulnerability is a use after free (CWE-416) flaw triggered during the handling of window icon asynchronous messages. The vulnerability is exploitable by an unauthenticated attacker over the network.
Business impact
The exploitation of this vulnerability can lead to a denial of service, causing the FreeRDP client or server to crash or become unresponsive. While the CVSS score of 7.5 indicates a high severity rating, the primary impact is limited to availability, potentially disrupting critical remote access workflows and business operations.
Remediation
Immediate Action: Update FreeRDP to version 3.29.0 or later to incorporate the necessary security fixes.
Proactive Monitoring: Monitor system logs for repeated crash events or unexpected service terminations related to the FreeRDP process.
Compensating Controls: Ensure that remote access services are restricted to trusted network segments to limit exposure to potential attackers.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability, administrators should prioritize updating all instances of FreeRDP to version 3.29.0. Applying this update is the most effective way to eliminate the risk of service disruption associated with this use after free flaw.