Improper Certificate Validation in FreeRDP - #VU152399
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose OAuth authorization codes and control authentication exchanges.
The vulnerability exists due to improper certificate validation in freerdp_http_request() in libfreerdp/utils/http.c when handling Azure AD or Azure Virtual Desktop authentication requests. A remote attacker can intercept and modify HTTPS authentication traffic to disclose OAuth authorization codes and control authentication exchanges.
Only clients using the Azure AD or Azure Virtual Desktop authentication path in builds with WITH_AAD enabled are affected.