{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/freerdp--3.29.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-67288"},{"cvss":7.5,"id":"CVE-2026-67300"},{"cvss":7.5,"id":"CVE-2026-67290"},{"cvss":7.5,"id":"CVE-2026-67296"},{"cvss":7.5,"id":"CVE-2026-67299"},{"cvss":7.5,"id":"CVE-2026-67301"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeRDP","FreeRDP (\u003c 3.29.0)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","vulnerability","remote-execution"],"_cs_type":"advisory","_cs_vendors":["FreeRDP"],"content_html":"\u003cp\u003eFreeRDP versions prior to 3.29.0 are susceptible to a null pointer dereference vulnerability within their smartcard cache request decoders. This issue occurs when the application handles SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. Specifically, the decoder fails to properly validate NDR (Network Data Representation) pointers for the 'LookupName' field. When smartcard emulation is enabled, an attacker can transmit a crafted smartcard cache request containing a NULL pointer for this field. When the client process attempts to execute a strlen() function call on this NULL pointer, it results in an immediate crash of the FreeRDP client process. This vulnerability (CVE-2026-67288) presents a high-impact denial-of-service risk for environments utilizing FreeRDP with smartcard features enabled.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target system utilizing FreeRDP with smartcard emulation features enabled.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an RDP connection to the target system.\u003c/li\u003e\n\u003cli\u003eAttacker negotiates smartcard redirection capabilities during the RDP handshake process.\u003c/li\u003e\n\u003cli\u003eAttacker sends a specially crafted SCARD_IOCTL_READCACHEA or SCARD_IOCTL_WRITECACHEA packet.\u003c/li\u003e\n\u003cli\u003eThe packet is structured to provide a NULL pointer in the 'LookupName' field of the request.\u003c/li\u003e\n\u003cli\u003eThe FreeRDP client process receives the malicious packet and passes it to the decoder.\u003c/li\u003e\n\u003cli\u003eThe decoder attempts to process the NULL pointer using the strlen() function.\u003c/li\u003e\n\u003cli\u003eThe process encounters a memory access violation, leading to an immediate termination of the FreeRDP application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition for the FreeRDP client process. In environments where FreeRDP is used for critical administrative access or remote workstation connectivity, this enables an attacker to disrupt operations, disconnect users, and prevent legitimate administrative access to remote systems. The vulnerability is exploitable over the network without requiring authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of FreeRDP to version 3.29.0 or higher to include the fix for CVE-2026-67288.\u003c/li\u003e\n\u003cli\u003eDisable smartcard emulation in FreeRDP configurations if it is not strictly required for business workflows to reduce the attack surface.\u003c/li\u003e\n\u003cli\u003eMonitor endpoint process logs for abnormal termination or crashes of the FreeRDP client executable (e.g., \u003ccode\u003exfreerdp\u003c/code\u003e or \u003ccode\u003ewfreerdp\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eWhile network-based detection is difficult due to the nature of the protocol, prioritize monitoring for unauthorized RDP connection attempts to sensitive infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:52:31Z","date_published":"2026-08-01T13:51:41Z","id":"https://feed.craftedsignal.io/briefs/2026-08-freerdp-dos/","summary":"A null pointer dereference vulnerability in FreeRDP prior to 3.29.0 allows remote attackers to trigger a crash in the client process via crafted smartcard cache requests.","title":"FreeRDP Denial of Service via Smartcard Cache Request","url":"https://feed.craftedsignal.io/briefs/2026-08-freerdp-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - FreeRDP (\u003c 3.29.0)","version":"https://jsonfeed.org/version/1.1"}