Use After Free Vulnerability in FreeRDP Remote Desktop Protocol Implementation
CVE-2026-23884
What is CVE-2026-23884?
FreeRDP, the open-source implementation of the Remote Desktop Protocol, has a vulnerability that occurs when handling offscreen bitmaps. In prior versions to 3.21.0, improper management of memory can leave pointer references that lead to a situation where freed memory is still accessible. An attacker controlling a malicious server can exploit this flaw by sending crafted update packets that might cause a client-side crash, leading to a Denial of Service (DoS) scenario. Additionally, heap corruption risks increase, potentially allowing for arbitrary code execution based on the memory allocator's behavior. The issue has been resolved in version 3.21.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeRDP < 3.21.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
