CVE-2026-56297: fallo de gravedad alta en FreeRDP
FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.3epss 0.5%
probabilidad de explotación
0.5%top 62% de las CVE
explotación observada
noninguna fuente lo reporta
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Productos afectados
FreeRDP · FreeRDPCVEs relacionadas — FreeRDP
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-32459CRITICALFreeRDP Out-Of-Bounds Read in ncrush_decompressEPSS 3.7%CVE-2022-24882CRITICALServer side NTLM does not properly check parameters in FreeRDPEPSS 2.8%CVE-2020-11019MEDIUMOut of bound read in update_recv in FreeRDPEPSS 2.5%CVE-2022-24883HIGHFreeRDP Server authentication might allow invalid credentials to passEPSS 2.3%CVE-2024-32039CRITICALFreeRDP Integer overflow & OutOfBound Write in clear_decompress_residual_dataEPSS 2.3%CVE-2020-11099LOWOOB Read in license_read_new_or_upgrade_license_packet in FreeRDPEPSS 2.1%