Heap Buffer Overflow in FreeRDP Windows Client Affects Clipboard Virtual Channel
CVE-2026-67305
9.4CRITICAL
What is CVE-2026-67305?
The FreeRDP Windows client prior to version 3.29.0 is susceptible to a heap buffer overflow vulnerability within its clipboard virtual channel functionality. The flaw occurs during the processing of CLIPRDR_FILE_CONTENTS_RESPONSE PDUs, specifically when not properly validating the size of data provided by the server against the allocated buffer. This oversight allows a malicious RDP server to send an excessively large data payload, leading to arbitrary heap memory corruption. If exploited, this vulnerability may enable remote code execution during clipboard paste operations, posing significant security risks to users.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
