CVE-2026-22853

CRITICAL

FreeRDP < 3.20.1 - Heap Buffer Overflow in RDPEAR NDR Array Reader

Title source: llm
STIX 2.1

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.

References (2)

Core 2
Core References

Scores

CVSS v3 9.8
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
freerdp/freerdp < 3.20.1
Published Jan 14, 2026
Tracked Since Feb 18, 2026