Use After Free Vulnerability in FreeRDP Remote Desktop Protocol Implementation
CVE-2026-23884

7.7HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2026-23884?

FreeRDP, the open-source implementation of the Remote Desktop Protocol, has a vulnerability that occurs when handling offscreen bitmaps. In prior versions to 3.21.0, improper management of memory can leave pointer references that lead to a situation where freed memory is still accessible. An attacker controlling a malicious server can exploit this flaw by sending crafted update packets that might cause a client-side crash, leading to a Denial of Service (DoS) scenario. Additionally, heap corruption risks increase, potentially allowing for arbitrary code execution based on the memory allocator's behavior. The issue has been resolved in version 3.21.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

FreeRDP < 3.21.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.