FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.26.0之前版本存在缓冲区错误漏洞,该漏洞源于平面位图解码器在解码RLE平面数据时存在堆越界写入,攻击者可通过大的nDstStep和nXDst绕过检查,导致写入超出内部临时缓冲区末尾。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44420 | 8.8 HIGH | FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_ |
| CVE-2026-44421 | 8.8 HIGH | FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass |
| CVE-2026-44422 | 7.5 HIGH | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion |
No comments yet