FreeRDP是FreeRDP团队开源的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.28.0之前版本存在缓冲区错误漏洞,该漏洞源于服务器在启用MS-RDPECAM摄像头设备枚举器通道时,扫描攻击者提供的DeviceName和VirtualChannelName字段以查找NUL终止符并超出边界解引用,允许恶意RDP客户端触发1到2字节的越界堆读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55827 | 7.5 HIGH | FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode |
| CVE-2026-57156 | FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing | |
| CVE-2026-57158 | FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-2353 |
No comments yet