#VU125347 Buffer Over-read in FreeRDP - CVE-2026-26271
Published: April 8, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to buffer over-read in freerdp_image_copy_from_icon_data() when processing crafted RDP window icon data. A remote attacker can send specially crafted icon data to disclose sensitive information.
The issue is reachable over the network when a client processes icon data from an RDP server or a man-in-the-middle position.