Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64621

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A double-free vulnerability exists when a FreeRDP client processes a specially crafted .rdp connection file. An attacker could convince a victim to open a malicious .rdp file, leading to a size-controlled double-free. This could potentially allow for arbitrary code execution on the affected system.

Отчет

This Important flaw in FreeRDP clients allows for arbitrary code execution when a user opens a specially crafted .rdp connection file. The vulnerability stems from a double-free condition during the parsing of the selectedmonitors field, which can be triggered by an attacker convincing a victim to open a malicious file. This risk is elevated as it affects default configurations of FreeRDP command-line interface clients.

Меры по смягчению последствий

The vulnerability is triggered by opening a malicious .rdp file. Users should exercise caution and avoid opening .rdp files from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2502766FreeRDP: FreeRDP: Double-free vulnerability via crafted .rdp file leading to potential remote code execution

EPSS

Процентиль: 23%
0.00304
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
12 дней назад

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.

CVSS3: 7.3
nvd
12 дней назад

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.

CVSS3: 7.3
debian
12 дней назад

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double- ...

CVSS3: 7.3
github
12 дней назад

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.

CVSS3: 7.3
fstec
26 дней назад

Уязвимость функции freerdp_client_rdp_file_apply_to_settings() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 23%
0.00304
Низкий

7.3 High

CVSS3