CVE-2026-67304

FreeRDP · FreeRDP

A NULL pointer dereference vulnerability in FreeRDP allows for service disruption during smartcard cleanup operations.

Executive summary

A NULL pointer dereference vulnerability in FreeRDP versions prior to 3.29.0 poses a high risk of application crashes.

Vulnerability

This vulnerability is a NULL pointer dereference (CWE-476) occurring during smartcard cleanup processes. The vulnerability is exploitable by an unauthenticated attacker over the network.

Business impact

Successful exploitation leads to a denial of service, causing the FreeRDP application to crash. Given the CVSS score of 7.5, this high-severity flaw can disrupt remote access workflows and organizational productivity, particularly for teams relying on RDP for infrastructure management.

Remediation

Immediate Action: Update FreeRDP to version 3.29.0 or later to incorporate the necessary memory safety fixes.

Proactive Monitoring: Monitor system logs for unexpected service terminations or recurring crash reports related to the FreeRDP process.

Compensating Controls: Ensure that remote access gateways are behind a firewall and restrict RDP access to trusted networks to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to maintain service availability. Administrators should prioritize patching all instances of FreeRDP to version 3.29.0 to eliminate the risk of service disruption caused by this NULL pointer dereference.