ZeroHour

CVE-2026-91949

large

Unauthenticated RDSTLS Negotiation Bypass in FreeRDP Server before 3.31.0

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

FreeRDP servers before version 3.31.0 contain a protocol negotiation bypass (CWE-693, protection mechanism failure) in which the server fails to enforce its own configured transport restrictions during RDP protocol selection. An unauthenticated remote attacker sends deliberately incompatible protocol negotiation requests, receives the expected negotiation failure response, but is still allowed to complete the TLS handshake and enter an RDSTLS session even when the server's policy explicitly disables RDSTLS. This effectively bypasses pre-authentication transport restrictions, giving the attacker an authenticated-looking channel into the RDP server without valid credentials, with the CVSS 4.0 vector indicating high confidentiality impact on the vulnerable and subsequent systems. Any deployment exposing a FreeRDP-based server (including products embedding FreeRDP) on an older version is affected, with the greatest risk to internet-exposed RDP endpoints. No public proof of concept is known and there is no evidence of in-the-wild exploitation at this time.

What to do: Upgrade FreeRDP server to version 3.31.0 or later immediately; if you run a vendor product that embeds FreeRDP (thin clients, remote access gateways, Linux terminal servers), check with the vendor for a patched build and update promptly. Until patched, remove RDP endpoints from direct internet exposure (restrict to VPN or allowlisted gateways) and audit logs for the attack signature: protocol negotiation failure responses followed by completed TLS handshakes and RDSTLS sessions.

Affected
FreeRDP (server component, including freerdp-shadow-server and third-party products embedding FreeRDP)before 3.31.0
Estimated exposure
largetens of thousands of internet-exposed RDP servers plausibly running FreeRDP-based stacks, with a larger embedded installed base in vendor products (hundreds of… — Public scan data shows roughly 3-4 million internet-exposed RDP endpoints on port 3389, and FreeRDP is the dominant open-source RDP implementation embedded in many thin-client, remote-access, and Linux terminal-server products, so its…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.

Weakness
CWE-693
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.