Ad

CVE-2026-25941

MEDIUM CVSS 3.1: 4.3 EPSS 0.14%
Updated Feb 25, 2026
Freerdp
Parameter Value
CVSS 4.3 (MEDIUM)
Affected Versions before 3.23.0
Type CWE-125 (Out-of-bounds Read), CWE-20 (Improper Input Validation)
Vendor Freerdp
Public PoC No

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server.

Versions 2.11.8 and 3.23.0 fix the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1