Remote Desktop Protocol Vulnerability in FreeRDP by FreeRDP
CVE-2026-55193
8.7HIGH
What is CVE-2026-55193?
FreeRDP, a free implementation of the Remote Desktop Protocol, has a vulnerability that allows attackers to manipulate the max_xmit_frag value in a way that could lead to a buffer overflow. Prior to version 3.27.0, FreeRDP clients did not properly bound this value, allowing a malicious gateway to send a fragment up to 65535 bytes. This could cause clients to crash and potentially allow for code execution via heap corruption. Users are advised to upgrade to version 3.27.0 or later to mitigate this risk.
Affected Version(s)
FreeRDP < 3.27.0
