FreeRDP是FreeRDP团队开源的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.28.0之前版本存在安全漏洞,该漏洞源于在32位构建中,libfreerdp/core/orders.c文件的update_read_delta_points函数中,将攻击者控制的点计数乘以sizeof(DELTA_POINT)时出现整数溢出,可能导致恶意RDP对等点分配过小的堆缓冲区并在初始化期间越界写入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55827 | 7.5 HIGH | FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode |
| CVE-2026-57157 | 6.5 MEDIUM | Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated Devic |
| CVE-2026-57158 | FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-2353 |
No comments yet