Junglewise Threat Intelligence

CVE-2026-55193: FreeRDP heap buffer overflow in TS Gateway RPC handling

CVE-2026-55193 · Severity: info · CVSS 8.6 · Published 2026-08-19

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is a Remote Desktop client library used to connect to Windows servers via the RDP protocol. A malicious TS Gateway server can crash FreeRDP clients or potentially execute arbitrary code by manipulating fragment size limits, allowing an attacker to write excessive data into a heap buffer and corrupt memory.

Technical details

This is a heap buffer overflow vulnerability in the RPC Gateway component of FreeRDP (prior to version 3.27.0). The vulnerable code in libfreerdp/core/gateway/rpc_bind.c accepts a server-controlled max_xmit_frag value without validating it against the 4088-byte ReceiveFragment allocation size. An attacker-controlled TS Gateway can advertise a fragment size of 65535 and subsequently send a response of that length, causing rpc_channel_read in rpc.c to write up to 65535 bytes into the smaller buffer. This triggers heap corruption, resulting in client crashes and potential remote code execution. The attack requires network connectivity to a malicious TS Gateway server and affects any FreeRDP client connecting through such a gateway. The fix was released in version 3.27.0 via bounds-checking patches to the RPC header processing.

Affected products

  • FreeRDP FreeRDP prior to 3.27.0

Timeline

  • 2026-08-19: disclosed
  • 2026-06-11: patched: Fixed in version 3.27.0

References

Related threats