GHSA-qjqr-mv8g-x357MediumCVSS 6.6

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

🔗 References (4)