CVE-2026-67301
FreeRDP · FreeRDP
An out of bounds read vulnerability in FreeRDP versions before 3.29.0 may allow for denial of service via polygon asynchronous messages.
Executive summary
An out of bounds read vulnerability in FreeRDP, affecting versions prior to 3.29.0, may result in service instability.
Vulnerability
This vulnerability is an out of bounds read (CWE-125) occurring during the processing of polygon asynchronous messages. It is exploitable by an unauthenticated attacker over the network.
Business impact
Exploitation of this flaw can lead to service crashes, causing significant disruption to remote connection services. The CVSS score of 7.5 confirms the high severity of the issue, primarily due to the potential for an unauthenticated user to remotely cause a denial of service condition.
Remediation
Immediate Action: Update to FreeRDP version 3.29.0 or newer to remediate the vulnerability.
Proactive Monitoring: Monitor for service crashes and analyze logs for malformed network packets that might correlate with attempts to trigger an out of bounds read.
Compensating Controls: Implement firewall rules to limit the exposure of the FreeRDP service to known and trusted IP addresses.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Security teams must prioritize updating to version 3.29.0 to ensure the integrity and availability of the FreeRDP software. Regular updates are the most effective defense against this and similar remote vulnerabilities.