Remote Desktop Protocol Implementation Vulnerability in FreeRDP
CVE-2026-33952
6MEDIUM
What is CVE-2026-33952?
FreeRDP, a widely used free implementation of the Remote Desktop Protocol, is affected by a vulnerability prior to version 3.24.2. An unvalidated auth_length field processed from the network can trigger an assertion failure in the function rts_read_auth_verifier_no_checks(). This vulnerability allows a malicious RDP Gateway to crash any FreeRDP client using RPC-over-HTTP transport, leading to a pre-authentication denial of service. This issue has been addressed in the release of version 3.24.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeRDP < 3.24.2
