Use of uninitialized resource in FreeRDP - #VU152394
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to use of an uninitialized resource in the FreeRDP progressive codec tile-upgrade path when processing crafted progressive graphics data. A remote attacker can send a crafted RDP graphics message to disclose sensitive information and cause a denial of service.
Exploitation requires the victim to connect to a malicious RDP server.