ZeroHour

CVE-2026-66401

PoC large

Out-of-bounds heap read in FreeRDP UVC H.264 parser enables DoS via malicious USB camera

CVSS 4.0
2.4 low
EPSS
<1%p11
Published
()
Modified
AI analysis

FreeRDP before 3.29.0 contains an out-of-bounds heap read (CWE-125) in its parser for the USB Video Class (UVC) H.264 extension unit: the code accesses the extension-unit GUID field without first validating the descriptor's length. A local attacker who plugs in a malicious USB video camera can trigger the out-of-bounds read during camera stream setup, crashing the FreeRDP process and causing a denial of service. The impact is availability-only - CVSS 4.0 rates it 2.4 (low) with no confidentiality or integrity impact - and exploitation requires physical access and a crafted USB camera device. Anyone running an affected FreeRDP version on systems where untrusted users can attach USB peripherals is potentially exposed. There is no evidence of exploitation in the wild: the flaw is not in CISA KEV, EPSS estimates a 0.2% 30-day exploitation probability, and the only public reference is the vendor advisory (GHSA-8jj2-67pg-j6mg).

What to do: Upgrade FreeRDP to 3.29.0 or later. As an interim mitigation, avoid using USB camera (UVC) redirection with untrusted devices and restrict physical access to machines running FreeRDP. Check installed versions via your package manager or 'freerdp --version' and prioritize hosts where local users can plug in peripherals.

Affected
FreeRDPall versions before 3.29.0
Estimated exposure
largelikely hundreds of thousands of installations or more; practical reach limited to hosts where USB camera (UVC) redirection is used — Based on deployment patterns: FreeRDP is the standard open-source RDP client bundled in many Linux desktop stacks, remote-desktop frontends, and thin-client products, but no public install-count data is available, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

Vendors
freerdp
Products
freerdp
Weakness
CWE-125
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.