Heap-based buffer overflow in FreeRDP - #VU134506
Published: June 15, 2026
FreeRDP
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the TS Gateway RPC fragment receive logic when processing RESPONSE fragments from a TS Gateway after RPC bind negotiation. A remote attacker can send a crafted bind_ack and subsequent oversized RESPONSE fragments to execute arbitrary code.
The issue affects FreeRDP clients using TS Gateway / RD Gateway transport, and can also be triggered by an active machine-in-the-middle on gateway traffic. Direct RDP connections that do not use the gateway RPC layer are not affected.