Executive brief
FreeRDP is an open-source implementation of the Remote Desktop Protocol used to provide remote access to graphical desktops. A vulnerability in the server-side clipboard component allows a malicious client to crash the server or potentially execute unauthorized code. This could lead to a total loss of service availability or the compromise of the server hosting the remote desktop sessions.
Technical details
A heap-based buffer overflow exists in FreeRDP's server-side clipboard (cliprdr) channel due to insufficient validation of the 'capabilitySetLength' field in CB_CLIP_CAPS PDUs. In 'cliprdr_server_receive_capabilities', the server uses a client-provided length to reallocate a heap buffer but subsequently performs a fixed-size write of a 12-byte structure (CLIPRDR_GENERAL_CAPABILITY_SET). An attacker can provide a length as small as 1 byte, resulting in an 11-byte out-of-bounds write. This vulnerability requires a network connection to a FreeRDP-based server with the clipboard channel enabled and low-privileged authentication. Successful exploitation can lead to a denial-of-service (DoS) or potential remote code execution (RCE) via heap corruption. The issue is resolved in version 3.26.0.
Affected products
- FreeRDP FreeRDP < 3.26.0
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published by maintainers
- 2026-05-29: disclosed: CVE published to NVD
- 2026-05-29: patched: Fix released in version 3.26.0