Vulnerabilities in FreeRDP

211 results
Vexday analysis

Com 147 CVEs catalogadas, o FreeRDP apresenta um volume considerável de vulnerabilidades históricas, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-125 (leitura fora dos limites de buffer), padrão recorrente em clientes de protocolo remoto e que pode facilitar vazamento de dados ou instabilidade da aplicação. O CVE de maior atenção no momento é CVE-2024-32459, com score EPSS de 0,0375, e a existência de 2 CVEs com PoC pública exige monitoramento contínuo por parte de equipes de resposta. O ritmo de 15 novas CVEs nos últimos 90 dias indica superfície de ataque em expansão ativa, reforçando a necessidade de ciclos de atualização frequentes em ambientes que utilizam esta solução de desktop remoto.

CVE-2026-24675HIGHFreeRDP has a Heap-use-after-free in urb_select_interfaceEPSS 0.5%CVE-2026-23948MEDIUMFreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()EPSS 0.5%CVE-2026-24676HIGHFreeRDP has a heap-use-after-free in audio_format_compatibleEPSS 0.5%CVE-2026-24681HIGHFreeRDP has a heap-use-after-free in urb_bulk_transfer_cbEPSS 0.5%CVE-2026-24491HIGHFreeRDP has a heap-use-after-free in video_timerEPSS 0.5%CVE-2026-26986MEDIUMFreeRDP has heap-use-after-free in rail_window_freeEPSS 0.5%CVE-2026-23884HIGHHeap-use-after-free in gdi_set_boundsEPSS 0.5%CVE-2026-23883HIGHHeap-use-after-free in update_pointer_newEPSS 0.5%CVE-2026-57158MEDIUMFreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530EPSS 0.5%CVE-2026-55194HIGHFreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatchEPSS 0.5%CVE-2026-63633HIGHFreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→clientEPSS 0.5%CVE-2026-25942MEDIUMFreeRDP has global-buffer-overflow in xf_rail_server_execute_resultEPSS 0.5%CVE-2026-91955HIGHFreeRDP before 3.31.0 Denial of Service via Desktop DimensionsEPSS 0.5%CVE-2026-91950HIGHFreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 WraparoundEPSS 0.5%CVE-2026-91949CRITICALFreeRDP 3.0.0 through 3.30.0 Protocol Negotiation BypassEPSS 0.4%CVE-2026-91960HIGHFreeRDP before 3.31.0 Integer Overflow Double FreeEPSS 0.4%CVE-2026-24680HIGHFreeRDP has a heap-use-after-free in update_pointer_new(SDL)EPSS 0.4%CVE-2026-44422HIGHFreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusionEPSS 0.4%CVE-2026-27950MEDIUMFreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong FileEPSS 0.4%CVE-2026-91946HIGHFreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphicsEPSS 0.4%