Type Confusion in FreeRDP - #VU131102
Published: May 12, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to type confusion in the RDPEAR NDR parser when processing crafted RDPEAR NDR data from an RDP server. A remote attacker can reuse a non-null NDR pointer ref-id across fields with incompatible expected NDR types to cause an out-of-bounds read.
User interaction is required because the client must connect to a malicious or compromised RDP server, and exploitation is reachable when RDPEAR or Remote Credential Guard is in use.