FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` decoded. The string is only used to compare against the redirection server certificate. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade freerdp3 | Jul 27, 2026 | Jul 27, 2026 |
| Oracle_linux | — | Upgrade freerdp-libsUpgrade libwinprUpgrade freerdpUpgrade freerdp-develUpgrade libwinpr-devel | Nov 21, 2024 | Apr 23, 2024 |
| Redhat_linux | — | Upgrade freerdpUpgrade libwinpr-develUpgrade freerdp-debuginfoUpgrade freerdp-debugsourceUpgrade libwinpr-debuginfoUpgrade freerdp-libs-debuginfoNo solution existsUpgrade freerdp-libsUpgrade freerdp-develUpgrade libwinpr | Nov 13, 2024 | Apr 23, 2024 |
| Rocky_linux | — | Upgrade libwinpr-debuginfoUpgrade libwinprUpgrade freerdp-develUpgrade freerdpUpgrade freerdp-libsUpgrade freerdp-debugsourceUpgrade freerdp-debuginfoUpgrade freerdp-libs-debuginfoUpgrade libwinpr-devel | Mar 18, 2025 | Apr 23, 2024 |
| Ubuntu | — | Upgrade libfreerdp3-3 | Apr 30, 2024 | Apr 23, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub