Out-of-bounds read in FreeRDP - #VU152404
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper length calculation in freerdp_assistance_parse_all_elements_of() when parsing a crafted Remote Assistance invitation file. A remote attacker can provide a crafted invitation file and its password to cause a denial of service.
User interaction is required to open the crafted file.