Heap Buffer Overflow in FreeRDP Affects Remote Desktop Protocol Implementation
CVE-2026-44420
8.8HIGH
What is CVE-2026-44420?
A vulnerability in FreeRDP prior to version 3.26.0 allows a malicious RDP client to exploit a weakness in the server-side clipboard channel. By sending a crafted CB_CLIP_CAPS Protocol Data Unit (PDU) with an insufficient capabilitySetLength, attackers can trigger a heap buffer overflow. This can lead to process crashes, resulting in remote denial of service (DoS) and potential code execution that compromises the server's memory integrity. Users are advised to upgrade to version 3.26.0 or later to mitigate this risk.
Affected Version(s)
FreeRDP < 3.26.0
