Junglewise Threat Intelligence

CVE-2026-64620: FreeRDP heap buffer overflow in crypto_rsa_common

CVE-2026-64620 · Severity: critical · CVSS 9.8 · Published 2026-07-20

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is an open-source implementation of the Remote Desktop Protocol used to provide remote access to computers. A security flaw in how the software handles encryption keys allows an unauthenticated attacker to crash the server or potentially take control of it. This occurs during the initial connection phase before a user even provides a password, making it a significant risk for any organization exposing FreeRDP-based services to the network.

Technical details

A heap-based buffer overflow exists in `libfreerdp/crypto/crypto.c` within the `crypto_rsa_common()` function. The vulnerability is caused by the use of `BN_bn2bin()`, which writes the result of a modular exponentiation into an output buffer before verifying if the result fits within the buffer's allocated size (`out_length`). On the server side, during the RDP Standard Security handshake, the `rdp_update_client_random()` function provides a fixed 32-byte buffer for the decrypted client random. Since the server's RSA public key is known, an unauthenticated attacker can craft a ciphertext that decrypts to a value up to the modulus length (e.g., 256 bytes for RSA-2048), resulting in an overflow of approximately 224 bytes. This occurs pre-authentication and allows for heap grooming and potential code execution. The issue is addressed in version 3.28.0.

Affected products

  • FreeRDP FreeRDP <= 3.27.1

Timeline

  • 2026-07-06: advisory: GitHub Security Advisory GHSA-pjqx-v446-x7fc published
  • 2026-07-20: disclosed: CVE-2026-64620 published to NVD

References

Related threats