Heap-based buffer overflow in FreeRDP - #VU146599
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in nego_send_negotiation_request when processing a server-controlled RoutingToken during RDP negotiation after redirection. A remote attacker can send a specially crafted server redirection PDU to execute arbitrary code.
Without chaining with a separate memory leak to defeat ASLR, the issue results in a client crash. User interaction is required because the victim must connect to a malicious RDP server.