CVE-2026-64620

CRITICAL

FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common

Title source: cna
STIX 2.1

Description

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common
https://www.vulncheck.com/advisories/freerdp-before-heap-buffer-overflow-via-crypto-rsa-common
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-pjqx-v446-x7fc)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc

Scores

CVSS v3 9.8
EPSS 0.0085
EPSS Percentile 54.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-122
Status published
Products (3)
FreeRDP/FreeRDP < 3.28.0
freerdp/freerdp < 3.28.0
FreeRDP/FreeRDP 3.28.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026