Heap-based buffer overflow in FreeRDP - #VU131104
Published: May 12, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in gdi_CacheToSurface when processing crafted RDPGFX PDUs from a server. A remote attacker can send crafted RDPGFX CacheToSurface messages to execute arbitrary code.
RDPGFX must be enabled, and user interaction is required to connect the client to an attacker-controlled RDP server.