FreeRDP vulnerability

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.

Published 15 Sep 2026Updated 16 Sep 20262 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.