Improper handling of exceptional conditions in FreeRDP - #VU146580
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass the configured transport security policy and disclose sensitive information.
The vulnerability exists due to improper handling of exceptional conditions in rdp_server_accept_nego() and protocol selection logic when processing an RDP negotiation failure followed by continued connection handling. A remote attacker can send an incompatible negotiation request and then continue the same connection to enter unintended RDSTLS processing to bypass the configured transport security policy and disclose sensitive information.
The issue is pre-authentication and can expose RDSTLS capabilities and related server-side parsers before the configured authentication mechanism runs.