Use-after-free in FreeRDP - #VU131101
Published: May 12, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to cause client-side memory corruption.
The vulnerability exists due to use-after-free in the RDPEAR NDR parser when processing crafted RDPEAR NDR data from an RDP server. A remote attacker can reuse a non-null NDR pointer ref-id across multiple logical pointer fields to cause client-side memory corruption.
User interaction is required because the client must connect to a malicious or compromised RDP server, and exploitation is reachable when RDPEAR or Remote Credential Guard is in use.