FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an unchecked `execResult->execResult` value received from the server, allowing an out-of-bounds read when the server sends an `execResult` value of 7 or greater. Version 3.23.0 fixes the issue.
CVSS Details
- CVSS 4.0 Base Score: 5.5 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade freerdp | Mar 2, 2026 | Feb 25, 2026 |
| Amazon Linux Ami 2 | — | Upgrade freerdp-debuginfoUpgrade freerdp-libsUpgrade libwinpr-develUpgrade freerdpUpgrade freerdp-develUpgrade libwinpr | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade freerdpUpgrade libwinpr-develUpgrade freerdp-debuginfoUpgrade freerdp-server-debuginfoUpgrade libwinprUpgrade libwinpr-debuginfoUpgrade freerdp-debugsourceUpgrade freerdp-libs-debuginfoUpgrade freerdp-serverUpgrade freerdp-libsUpgrade freerdp-devel | Apr 7, 2026 | Feb 25, 2026 |
| Debian | — | Upgrade freerdp3 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 25, 2026 |
| Ubuntu | — | Upgrade libfreerdp3-3 | Mar 19, 2026 | Feb 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub