CVE-2026-64620
FreeRDP versions before 3.28.0 contain a heap‑based buffer overflow that can be triggered during the RDP handshake. An unauthenticated attacker can send a crafted packet that overflows a 32‑byte server buffer, causing the server to crash and deny service before authentication.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
FreeRDP 3.27.1 and earlier. Users running older FreeRDP servers that accept RDP Standard Security connections are affected.
Real-world impact
An attacker can send a specially crafted RDP packet that overflows a server buffer, causing the server to crash and deny remote desktop service. This can be used to disrupt services without any authentication or user interaction.
Why this severity
The CVSS score of 9.3 reflects the high impact of the vulnerability: it allows a remote attacker to cause a denial of service with no authentication or user interaction, and the flaw is easy to exploit with low effort.
What to do about it
- 01Upgrade FreeRDP to version 3.28.0 or later.
- 02Restart the FreeRDP service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/FreeRDP/FreeRDP/commit/1f7a…patch
- github.com/FreeRDP/FreeRDP/security/ad…exploitmitigationvendor advisory
- vulncheck.com/advisories/freerdp-before-h…patchthird party advisory