Use of hard-coded credentials in FreeRDP - #VU152398
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose private keys.
The vulnerability exists due to the use of hard-coded credentials in winpr-makecert PFX export handling when creating PFX output without an explicit password. A local user can use the fixed password to open PFX output and disclose private keys.
User interaction is required for a user to run winpr-makecert.