NULL pointer dereference in FreeRDP - #VU146585
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in gdi_surface_bits when processing a surface bits command that claims to use NSCodec. A remote attacker can send a specially crafted RDP server message to cause a denial of service.
User interaction is required to connect to a malicious server, and the issue occurs when the client has not enabled NSCodec.