SB20260928133 - Multiple vulnerabilities in FreeRDP
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) NULL pointer dereference (CVE-ID: N/A)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the client video redirection channel when processing video redirection messages in an incorrect order. A remote attacker can send video redirection messages in an incorrect order to cause a denial of service.
User interaction is required.
2) Use of uninitialized resource (CVE-ID: N/A)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in the FreeRDP progressive codec tile-upgrade path when processing crafted progressive graphics data. A remote attacker can send a crafted RDP graphics message to disclose sensitive information and cause a denial of service.
Exploitation requires the victim to connect to a malicious RDP server.
3) Incorrect permission assignment for critical resource (CVE-ID: N/A)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose private-key information.
The vulnerability exists due to incorrect permission assignment for a critical resource in the soft-smartcard PKINIT private-key temporary file when writing a PEM private key to a shared system temporary directory with a permissive umask. A local user can read the active private-key copy to disclose private-key information.
Exploitation requires the victim to invoke soft-smartcard logon with the cert: and key: suboptions on a multi-user Unix host.
4) Incorrect permission assignment for critical resource (CVE-ID: N/A)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose private keys.
The vulnerability exists due to incorrect permission assignment for critical resources in the winpr-makecert certificate-output file creation routine when creating private-key or PFX output files. A local user can read output files created with permissive permissions to disclose private keys.
User interaction is required for a user to run winpr-makecert, and direct disclosure requires an output directory the user can traverse.
5) Use of hard-coded credentials (CVE-ID: N/A)
CWE-ID: CWE-798 - Use of Hard-coded Credentials
CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose private keys.
The vulnerability exists due to the use of hard-coded credentials in winpr-makecert PFX export handling when creating PFX output without an explicit password. A local user can use the fixed password to open PFX output and disclose private keys.
User interaction is required for a user to run winpr-makecert.
6) Improper Certificate Validation (CVE-ID: N/A)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose OAuth authorization codes and control authentication exchanges.
The vulnerability exists due to improper certificate validation in freerdp_http_request() in libfreerdp/utils/http.c when handling Azure AD or Azure Virtual Desktop authentication requests. A remote attacker can intercept and modify HTTPS authentication traffic to disclose OAuth authorization codes and control authentication exchanges.
Only clients using the Azure AD or Azure Virtual Desktop authentication path in builds with WITH_AAD enabled are affected.
7) Division by zero (CVE-ID: N/A)
CWE-ID: CWE-369 - Divide By Zero
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to divide by zero in the freerdp-shadow-cli shadow frame encoder when processing a client-supplied Frame Acknowledge PDU. A remote user can send a Frame Acknowledge PDU containing a frame ID greater than the server-sent frame ID to cause a denial of service.
The server provides frame IDs in Surface Frame Marker PDUs, making the required acknowledgment value deterministic.
8) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in convert_filedescriptors_to_file_list() when processing server-supplied clipboard file descriptors. A remote attacker can supply a crafted cFileName containing path traversal sequences to disclose sensitive information.
User interaction is required to paste the crafted clipboard entry into a file manager.
9) Improper Null Termination (CVE-ID: N/A)
CWE-ID: CWE-170 - Improper Null Termination
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper null termination in convert_filedescriptors_to_file_list() when processing a crafted FileGroupDescriptorW clipboard response after the victim pastes clipboard files. A remote attacker can send an odd-length FILEDESCRIPTORW blob with a non-NUL-terminated cFileName field to cause a denial of service.
Only Unix desktop clients with WITH_FUSE enabled are affected.
10) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper length calculation in freerdp_assistance_parse_all_elements_of() when parsing a crafted Remote Assistance invitation file. A remote attacker can provide a crafted invitation file and its password to cause a denial of service.
User interaction is required to open the crafted file.
Remediation
Install update from vendor's website.
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v7-9jp5-wqj2
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4mpr-hmqx-83q8
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q9p9-j22r-577p
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2jfv-j3wx-5cg4
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h44v-39x6-9xvg
- https://github.com/FreeRDP/FreeRDP/commit/7e0a52a12449fc8a6ca1b108c22ffec47cbeba28
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6vjv-4hm3-6698
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c3rh-2hv6-7hf2
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp2r-gm4v-wvq2
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-gvq8-v2fm-ffxv