Out-of-Bounds Read Vulnerability in FreeRDP Remote Desktop Implementation
CVE-2026-25942
What is CVE-2026-25942?
The FreeRDP implementation of the Remote Desktop Protocol contains a vulnerability due to unsafe indexing of an array with user-provided input. Specifically, before version 3.23.0, the function xf_rail_server_execute_result does not properly validate the execResult value received from the server, which can result in an out-of-bounds read if the server sends an execResult value of 7 or higher. This flaw can potentially allow an attacker to read sensitive information from unintended memory locations. Version 3.23.0 addresses this issue by implementing necessary checks on the execResult value.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeRDP < 3.23.0
