cvedb.io
CVE-2026-44420
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2026-05-29T20:16:24.383 · Last modified 2026-06-30T03:19:54.110

Summary

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process (remote DoS) and may be exploitable for code execution because it corrupts heap memory. This vulnerability is fixed in 3.26.0.

Affected products

freerdp — freerdp

Does this affect you?

Add your gear to cvedb and we'll alert you only when freerdp ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.