Junglewise Threat Intelligence

CVE-2026-55194: FreeRDP heap buffer overflow in RPC gateway response handling

CVE-2026-55194 · Severity: critical · CVSS 9.8 · Published 2026-08-19

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), used to enable remote desktop access to Windows and other systems. A malicious Terminal Server Gateway can send a specially crafted response that causes the FreeRDP client to write data beyond the bounds of an internal buffer, crashing the client or potentially allowing the attacker to execute arbitrary code on the victim's computer.

Technical details

The vulnerability is a heap buffer overflow in the rpc_client_recv_fragment function within libfreerdp/core/gateway/rpc_client.c. The root cause is that the code allocates buffer capacity based on the server-declared alloc_hint value rather than validating against the actual StubLength that will be written. A malicious TS Gateway can send a PTYPE_RESPONSE packet with a small alloc_hint but a much larger frag_length, causing Stream_Write to overflow the 4096-byte pdu->s buffer. The attack requires a network-reachable TS Gateway or a man-in-the-middle position; no user interaction or prior authentication is strictly required to trigger the overflow. Successful exploitation can lead to process crash (denial of service) or heap corruption enabling remote code execution. The vulnerability is fixed in version 3.27.0.

Affected products

  • FreeRDP FreeRDP prior to 3.27.0

Timeline

  • 2026-08-19: disclosed
  • 2026-06-11: patched: Fix merged in PR #12873 and released in version 3.27.0

References

Related threats