ZeroHour

CVE-2026-67296

PoC large

Unauthenticated Remote DoS in FreeRDP RDPEI Server Channel Handling

CVSS 4.0
8.7 high
EPSS
<1%p30
Published
()
Modified
AI analysis

FreeRDP before 3.29.0 fails to validate the maximum PDU body length in its RDPEI (RDP input extension) server channel handler before allocating a stream, enabling memory exhaustion. A malicious RDP client can connect to a FreeRDP-based RDP server and send a header-only RDPEI message declaring an oversized body length, forcing the server to allocate excessive memory and crash or stall the service. An attacker gains unauthenticated remote denial of service with no confidentiality or integrity impact, per the CVSS 4.0 vector (VA:H only). All FreeRDP releases prior to 3.29.0 are affected, but only deployments acting as RDP servers that accept connections from untrusted clients (e.g., shadow server, products embedding FreeRDP server libraries) are realistically exposed. No exploitation has been reported in the wild and the flaw is absent from CISA KEV; a public vendor security advisory (GHSA-jm8r-22j6-4m4v) exists and EPSS is low at 0.3%.

What to do: Upgrade FreeRDP to 3.29.0 or later, or install vendor/distribution backported packages. Operators running FreeRDP-based RDP servers (e.g., freerdp-shadow or products embedding the server libraries) should restrict RDP listener exposure with firewall rules or VPN access and watch for memory-exhaustion crashes. Verify the deployed version via package changelogs or 'freerdp --version' to confirm the fix is present.

Affected
FreeRDPall versions before 3.29.0
Estimated exposure
large≈10,000–100,000 FreeRDP-based RDP servers (of millions of total FreeRDP client-library installs) — FreeRDP is the dominant open-source RDP implementation bundled with virtually every major Linux distribution and embedded in thin clients, VDI gateways and remote-access products, but this server-side flaw only reaches hosts running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

Vendors
freerdp
Products
freerdp
Weakness
CWE-20
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.