CVE-2026-67300
Last modified
CVE-2026-67300 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). The parser frees those nested buffers after the callback returns, so the queued async message later dispatches stale pointers, potentially causing memory corruption or a client crash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FreeRDP | FreeRDP | < 3.29.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-67300?
How severe is CVE-2026-67300?
How do I fix CVE-2026-67300?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67294FreeRDP before 3.29.0 improperly validates the Extended Key …9.3
- CVE-2026-67295FreeRDP before 3.29.0 fails to properly validate server-supp…6.3
- CVE-2026-67296FreeRDP before 3.29.0 contains a denial of service vulnerabi…8.7
- CVE-2026-67297FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIM…8.7
- CVE-2026-67298FreeRDP versions 3.28.0 and earlier contain a heap buffer ov…8.7
- CVE-2026-67299FreeRDP before 3.29.0 contains a client-side heap use-after-…8.7
- CVE-2026-67301FreeRDP before 3.29.0 contains out-of-bounds read vulnerabil…8.7
- CVE-2026-67302FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains…5.3
- CVE-2026-67303FreeRDP before 3.29.0 contains a reachable assertion (WINPR_…5.3
- CVE-2026-67304FreeRDP before 3.29.0 contains a null pointer dereference vu…8.7
- CVE-2026-67305FreeRDP Windows client before 3.29.0 contains a heap buffer …9.4
- CVE-2026-67306FreeRDP versions 3.28.0 and earlier contain an out-of-bounds…5.4
Are you affected by CVE-2026-67300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
