Out-of-Bounds Read Vulnerability in FreeRDP Remote Desktop Implementation
CVE-2026-25942

5.5MEDIUM

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
25 February 2026

What is CVE-2026-25942?

The FreeRDP implementation of the Remote Desktop Protocol contains a vulnerability due to unsafe indexing of an array with user-provided input. Specifically, before version 3.23.0, the function xf_rail_server_execute_result does not properly validate the execResult value received from the server, which can result in an out-of-bounds read if the server sends an execResult value of 7 or higher. This flaw can potentially allow an attacker to read sensitive information from unintended memory locations. Version 3.23.0 addresses this issue by implementing necessary checks on the execResult value.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

FreeRDP < 3.23.0

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.