Junglewise Threat Intelligence

CVE-2026-44420: FreeRDP heap buffer overflow in server-side clipboard channel

CVE-2026-44420 · Severity: high · CVSS 8.8 · Published 2026-05-29

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is an open-source implementation of the Remote Desktop Protocol used to provide remote access to graphical desktops. A vulnerability in the server-side clipboard component allows a malicious client to crash the server or potentially execute unauthorized code. This could lead to a total loss of service availability or the compromise of the server hosting the remote desktop sessions.

Technical details

A heap-based buffer overflow exists in FreeRDP's server-side clipboard (cliprdr) channel due to insufficient validation of the 'capabilitySetLength' field in CB_CLIP_CAPS PDUs. In 'cliprdr_server_receive_capabilities', the server uses a client-provided length to reallocate a heap buffer but subsequently performs a fixed-size write of a 12-byte structure (CLIPRDR_GENERAL_CAPABILITY_SET). An attacker can provide a length as small as 1 byte, resulting in an 11-byte out-of-bounds write. This vulnerability requires a network connection to a FreeRDP-based server with the clipboard channel enabled and low-privileged authentication. Successful exploitation can lead to a denial-of-service (DoS) or potential remote code execution (RCE) via heap corruption. The issue is resolved in version 3.26.0.

Affected products

  • FreeRDP FreeRDP < 3.26.0

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published by maintainers
  • 2026-05-29: disclosed: CVE published to NVD
  • 2026-05-29: patched: Fix released in version 3.26.0

References

Related threats