Heap Buffer Overflow in FreeRDP Windows Client Affects Clipboard Virtual Channel
CVE-2026-67305

9.4CRITICAL

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67305?

The FreeRDP Windows client prior to version 3.29.0 is susceptible to a heap buffer overflow vulnerability within its clipboard virtual channel functionality. The flaw occurs during the processing of CLIPRDR_FILE_CONTENTS_RESPONSE PDUs, specifically when not properly validating the size of data provided by the server against the allocated buffer. This oversight allows a malicious RDP server to send an excessively large data payload, leading to arbitrary heap memory corruption. If exploited, this vulnerability may enable remote code execution during clipboard paste operations, posing significant security risks to users.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hyperlyz
.