FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.26.0之前版本存在安全漏洞,该漏洞源于恶意RDP服务器可通过发送特制RDPGFX PDU触发客户端堆缓冲区溢出写入,gdi_CacheToSurface中验证目标矩形但使用原始cacheEntry->width/height进行复制,可能导致客户端崩溃或代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44420 | 8.8 HIGH | FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_ |
| CVE-2026-45700 | 7.7 HIGH | Heap-buffer-overflow write in planar bitmap decoder |
| CVE-2026-44422 | 7.5 HIGH | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion |
No comments yet