Heap-based buffer overflow in FreeRDP - #VU146584
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in nego_send_negotiation_request when processing an oversized LB_LOAD_BALANCE_INFO routing token during connection negotiation. A remote attacker can send a crafted Server Redirection PDU to cause a denial of service.
The issue is reachable before any security protocol handshake completes, and user interaction is required to connect to a malicious server or a machine-in-the-middle server.