Improper Validation of Array Index in FreeRDP - #VU146593

 

Improper Validation of Array Index in FreeRDP - #VU146593

Published: September 1, 2026


Vulnerability identifier: #VU146593
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-129
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information, modify memory, and cause a denial of service.

The vulnerability exists due to improper validation of array index in X11 monitor selection in xf_detect_monitors when processing an attacker-supplied .rdp connection file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information, modify memory, and cause a denial of service.

No server connection is required because the issue is triggered during PreConnect before any RDP traffic, and user interaction is required to open the crafted .rdp file.


Affected software

FreeRDP

Remediation

Install security update from vendor's website.

FreeRDP - update to 3.31.0

External References

Related Security Bulletins