Executive brief
FreeRDP is an open-source implementation of the Remote Desktop Protocol used to connect to remote computers. A vulnerability in the client software allows a malicious server to crash the user's connection or potentially execute unauthorized code on the user's computer. This occurs when the client connects to a compromised or malicious server while the RDPGFX feature is enabled.
Technical details
A heap-based buffer overflow exists in FreeRDP's gdi_CacheToSurface function within the RDPGFX pipeline. The vulnerability is caused by improper validation of destination rectangles; specifically, the code validates a rectangle that has been clamped to UINT16_MAX, but subsequently performs a memory copy using the original, unclamped width and height from the cache entry. An attacker-controlled RDP server can exploit this by sending crafted RDPGFX PDUs to trigger a large out-of-bounds heap write. This can result in a denial-of-service (client crash) or potential remote code execution on the client machine. The issue is fixed in version 3.26.0 by implementing bounds checks against the actual copy dimensions.
Affected products
- FreeRDP FreeRDP < 3.26.0
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: NVD publication date