Heap Buffer Overflow in FreeRDP Affected Software
CVE-2026-33982
7.1HIGH
What is CVE-2026-33982?
A heap buffer overflow vulnerability exists in FreeRDP, a free implementation of the Remote Desktop Protocol, affecting versions prior to 3.24.2. This flaw arises due to an improper memory allocation handling in the function winpr_aligned_offset_recalloc(), allowing unauthorized access to memory. This may result in the compromise of system integrity and confidentiality. Users are strongly advised to upgrade to version 3.24.2 or later to mitigate potential risks.
Affected Version(s)
FreeRDP < 3.24.2
