Out-of-bounds read in FreeRDP - #VU134509
Published: June 15, 2026
FreeRDP
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to an out-of-bounds read in glyph_cache_get() in the glyph cache when processing crafted glyph fragments from a malicious RDP server. A remote attacker can send crafted glyph orders that cause an out-of-bounds heap read to disclose sensitive information and cause a denial of service.
User interaction is required because the victim must connect to the attacker's RDP server.