Heap-based buffer overflow in FreeRDP - #VU139935
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service and perform out-of-bounds memory access.
The vulnerability exists due to a heap-based buffer overflow in kerberos_DecryptMessage when processing a peer-supplied GSS Wrap token during CredSSP/NLA. A remote user can send a specially crafted token with an oversized EC field to cause a denial of service and perform out-of-bounds memory access.
Exploitation requires a completed Kerberos NLA context, and both a malicious server to a client and an authenticated client to a server can reach the vulnerable code path.