{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/freerdp--3.30.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-72745"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeRDP","FreeRDP (\u003c 3.30.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["FreeRDP"],"content_html":"\u003cp\u003eFreeRDP versions prior to 3.30.0 contain a critical memory safety vulnerability in the \u003ccode\u003ekerberos_DecryptMessage\u003c/code\u003e function located within \u003ccode\u003ewinpr/libwinpr/sspi/Kerberos/kerberos.c\u003c/code\u003e. The vulnerability arises from improper validation of the 16-bit EC (extra count) field within a GSS Wrap token as defined in RFC 4121. While the implementation validates the RRC field and the total buffer length, it fails to perform bounds checking on the EC field before using it in pointer arithmetic to calculate encrypted regions within the buffer.\u003c/p\u003e\n\u003cp\u003eAn attacker acting as a malicious peer (either client or server) can provide a specially crafted EC value up to 0xFFFF during the CredSSP or NLA authentication handshake. This causes the decryption logic to compute memory offsets outside the allocated ~60-byte token buffer. Because the library performs in-place decryption for AES-CTS-HMAC enctypes before verifying the HMAC integrity, the vulnerability allows for both out-of-bounds reads and writes. This can result in denial of service, sensitive information disclosure, or potential arbitrary code execution through memory corruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a malicious peer to trigger memory corruption on a system running an affected version of FreeRDP. This impacts any environment using FreeRDP-based clients or servers for remote access. Potential outcomes include crash-based denial of service, leakage of sensitive memory contents, or potential escalation to arbitrary code execution, depending on the memory layout and attacker capabilities. This vulnerability affects cross-platform deployments given FreeRDP's usage on Linux, macOS, and Windows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of FreeRDP to version 3.30.0 or higher immediately to address the missing bounds check in the kerberos_DecryptMessage function.\u003c/li\u003e\n\u003cli\u003eInventory all services and applications within the environment that utilize the FreeRDP library or the WinPR component to ensure comprehensive patching.\u003c/li\u003e\n\u003cli\u003eMonitor system logs for frequent crashes or unexpected termination of RDP-related processes, which may indicate attempted exploitation of this memory corruption vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-11T14:03:11Z","date_published":"2026-08-11T14:03:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-freerdp-oob/","summary":"FreeRDP versions before 3.30.0 are vulnerable to memory corruption in the kerberos_DecryptMessage function, allowing a malicious peer to perform out-of-bounds read and write operations via crafted GSS Wrap tokens during authentication.","title":"Out-of-Bounds Memory Corruption in FreeRDP","url":"https://feed.craftedsignal.io/briefs/2026-08-freerdp-oob/"}],"language":"en","title":"CraftedSignal Threat Feed - FreeRDP (\u003c 3.30.0)","version":"https://jsonfeed.org/version/1.1"}