Heap Buffer Overflow in FreeRDP Affects Remote Desktop Protocol Implementation
CVE-2026-44420

8.8HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-44420?

A vulnerability in FreeRDP prior to version 3.26.0 allows a malicious RDP client to exploit a weakness in the server-side clipboard channel. By sending a crafted CB_CLIP_CAPS Protocol Data Unit (PDU) with an insufficient capabilitySetLength, attackers can trigger a heap buffer overflow. This can lead to process crashes, resulting in remote denial of service (DoS) and potential code execution that compromises the server's memory integrity. Users are advised to upgrade to version 3.26.0 or later to mitigate this risk.

Affected Version(s)

FreeRDP < 3.26.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.