Heap-based buffer overflow in FreeRDP - CVE-2026-44420
Published: May 12, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the server-side clipboard (cliprdr) channel capability parsing routine when processing a CB_CLIP_CAPS PDU with an undersized capabilitySetLength value. A remote user can send a specially crafted CB_CLIP_CAPS PDU to execute arbitrary code.
Affected systems must have the cliprdr server channel enabled.