FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.26.0之前版本存在安全漏洞,该漏洞源于恶意RDP客户端可通过发送具有过小capabilitySetLength的CB_CLIP_CAPS PDU触发服务器端剪贴板通道的堆缓冲区溢出写入,可能导致服务器进程崩溃或代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44421 | 8.8 HIGH | FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass |
| CVE-2026-45700 | 7.7 HIGH | Heap-buffer-overflow write in planar bitmap decoder |
| CVE-2026-44422 | 7.5 HIGH | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion |
No comments yet