CVE-2026-67300
FreeRDP · FreeRDP
A use after free vulnerability in FreeRDP prior to 3.29.0 allows for potential denial of service through the asynchronous message proxy.
Executive summary
A use after free vulnerability in FreeRDP, affecting versions prior to 3.29.0, creates a risk of denial of service attacks.
Vulnerability
This is a use after free (CWE-416) vulnerability that occurs within the asynchronous message proxy functionality of FreeRDP. The vulnerability is accessible to unauthenticated attackers over the network.
Business impact
Successful exploitation can result in the termination of the FreeRDP service, leading to system downtime. With a CVSS score of 7.5, the vulnerability is considered high risk because it directly impacts the availability of remote desktop connectivity, which is often a critical business dependency.
Remediation
Immediate Action: Upgrade all deployments of FreeRDP to version 3.29.0 or higher immediately.
Proactive Monitoring: Review security and system event logs for unusual activity or frequent service restarts that may indicate an attempt to trigger this vulnerability.
Compensating Controls: Utilize network-level access controls or VPNs to restrict access to the FreeRDP service to authorized users only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
It is critical to address this vulnerability by applying the vendor-supplied update to version 3.29.0. Organizations should treat this as a high-priority maintenance task to maintain the stability and security of their remote access infrastructure.