Use-after-free in FreeRDP - CVE-2026-67299
Published: July 16, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the async update message proxy for WINDOW_ICON_ORDER when processing crafted RAIL Window Alternate Secondary Orders with WINDOW_ORDER_ICON. A remote attacker can send a specially crafted RDP update order to cause a denial of service.
Exploitation requires AsyncUpdate to be enabled on the client.