Remote Desktop Protocol Vulnerability in FreeRDP Affects Unauthorized Client Authentication
CVE-2026-73241
8.3HIGH
What is CVE-2026-73241?
FreeRDP is a widely used open-source implementation of the Remote Desktop Protocol. In versions prior to 3.30.0, a vulnerability exists in the server-side RDSTLS component. The issue arises when the system accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES Protocol Data Unit (PDU) while it is supposed to be waiting for the RDSTLS_TYPE_AUTHREQ. This situation leaves the resultCode set to RDSTLS_RESULT_SUCCESS, which can be exploited by remote, unauthenticated clients to bypass critical authentication checks, including the RedirectionGuid, username, domain, and password requirements. The vulnerability has been addressed in version 3.30.0.
Affected Version(s)
FreeRDP < 3.30.0
