Out-of-bounds write in FreeRDP - #VU138640
Published: July 20, 2026
FreeRDP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a heap-based buffer overflow in a paste consumer process.
The vulnerability exists due to an out-of-bounds write in CliprdrStream_Read when processing a server-supplied CB_FILECONTENTS_RESPONSE for an IStream::Read request. A remote attacker can send a crafted clipboard file contents response with an oversized length field to cause a heap-based buffer overflow in a paste consumer process.
This issue affects the Windows client path and user interaction is required to paste server-offered clipboard file contents.