Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-67305: FreeRDP Windows client before 3.29.0: Remote code execution via clipboard exploit

CVE-2026-67305 CVE-2026-67305
Summary

The FreeRDP Windows client has a security flaw that allows an attacker to execute malicious code on a user's computer. This can happen if a user connects to a malicious Remote Desktop server and performs a paste operation. To protect against this, update the FreeRDP client to version 3.29.0 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
freerdp freerdp < 3.29.0
Original title
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server...
Original description
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation.
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 1 Aug 2026 · Updated: 4 Aug 2026 · First seen: 1 Aug 2026