Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-64620: FreeRDP before 3.28.0 allows unauthorized denial of service
CVE-2026-64620
CVE-2026-64620
Summary
FreeRDP versions 3.27.1 and earlier are vulnerable to a denial of service attack. An attacker can send a specially crafted message to the server, causing it to run out of memory. To protect your system, update to version 3.28.0 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| freerdp | freerdp | < 3.28.0 |
Original title
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the c...
Original description
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-122
Heap-based Buffer Overflow
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026