CVE-2026-66401
PoC largeOut-of-bounds heap read in FreeRDP UVC H.264 parser enables DoS via malicious USB camera
FreeRDP before 3.29.0 contains an out-of-bounds heap read (CWE-125) in its parser for the USB Video Class (UVC) H.264 extension unit: the code accesses the extension-unit GUID field without first validating the descriptor's length. A local attacker who plugs in a malicious USB video camera can trigger the out-of-bounds read during camera stream setup, crashing the FreeRDP process and causing a denial of service. The impact is availability-only - CVSS 4.0 rates it 2.4 (low) with no confidentiality or integrity impact - and exploitation requires physical access and a crafted USB camera device. Anyone running an affected FreeRDP version on systems where untrusted users can attach USB peripherals is potentially exposed. There is no evidence of exploitation in the wild: the flaw is not in CISA KEV, EPSS estimates a 0.2% 30-day exploitation probability, and the only public reference is the vendor advisory (GHSA-8jj2-67pg-j6mg).
What to do: Upgrade FreeRDP to 3.29.0 or later. As an interim mitigation, avoid using USB camera (UVC) redirection with untrusted devices and restrict physical access to machines running FreeRDP. Check installed versions via your package manager or 'freerdp --version' and prioritize hosts where local users can plug in peripherals.
| FreeRDP | all versions before 3.29.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.
- Vendors
- freerdp
- Products
- freerdp
- Weakness
- CWE-125
- Vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.