Improper Null Termination in FreeRDP - #VU152403
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper null termination in convert_filedescriptors_to_file_list() when processing a crafted FileGroupDescriptorW clipboard response after the victim pastes clipboard files. A remote attacker can send an odd-length FILEDESCRIPTORW blob with a non-NUL-terminated cFileName field to cause a denial of service.
Only Unix desktop clients with WITH_FUSE enabled are affected.