Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-57156: FreeRDP: Malicious RDP peer can cause memory corruption
CVE-2026-57156
CVE-2026-57156
Summary
FreeRDP clients are affected. An attacker can exploit this vulnerability to cause memory corruption, potentially leading to crashes or other security issues. Update to version 3.28.0 or later to fix the issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| freerdp | freerdp | < 3.28.0 |
Original title
FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing
Original description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fixed in version 3.28.0.
nvd CVSS4.0
8.6
Vulnerability type
CWE-122
Heap-based Buffer Overflow
CWE-190
Integer Overflow
Published: 10 Jul 2026 · Updated: 16 Jul 2026 · First seen: 10 Jul 2026