Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91958

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

A flaw was found in FreeRDP. This vulnerability allows a remote attacker to trigger out-of-bounds memory access by crafting a malicious Remote Desktop Protocol (RDP) connection file. When a user opens this file, the FreeRDP client fails to properly validate array values, leading to a heap buffer overflow. This can result in a denial of service, causing the application to crash, and potentially lead to information disclosure or arbitrary code execution.

Меры по смягчению последствий

To mitigate this issue, users should exercise caution and avoid opening RDP connection files from untrusted or unknown sources. This vulnerability requires user interaction with a malicious file to be exploited.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2533958FreeRDP: FreeRDP: Denial of service and potential code execution via malicious RDP file

EPSS

Процентиль: 10%
0.00199
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
4 дня назад

[GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection]

CVSS3: 6.6
nvd
4 дня назад

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

CVSS3: 6.6
debian
4 дня назад

FreeRDP versions before 3.31.0 fail to validate MonitorIds array value ...

CVSS3: 6.6
github
4 дня назад

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

EPSS

Процентиль: 10%
0.00199
Низкий

6.6 Medium

CVSS3