Heap-Based Buffer Overflow in FreeRDP Clipboard Client
CVE-2026-68579
8.7HIGH
What is CVE-2026-68579?
FreeRDP versions prior to 3.30.0 are susceptible to a heap-based buffer overflow vulnerability in the clipboard client's CliprdrStream_Read function. This occurs when an OLE paste consumer, such as explorer.exe, interacts with a malicious or compromised RDP server that returns oversized clipboard file contents. The server's response, which improperly writes data outside the bounds of a fixed-size buffer, can lead to an out-of-bounds write operation. This flaw may allow an attacker to manipulate the heap data of the paste consumer, posing significant security risks.
Affected Version(s)
FreeRDP 0 < 3.30.0
FreeRDP 3.30.0
