{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/freerdp-3.27.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-64620"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeRDP (\u003c=3.27.1)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","buffer-overflow","denial-of-service","freerdp","cve","network"],"_cs_type":"advisory","_cs_vendors":["FreeRDP Project"],"content_html":"\u003cp\u003eA critical heap-based buffer overflow, identified as CVE-2026-64620, affects FreeRDP versions prior to 3.28.0 (specifically, 3.27.1 and earlier). This vulnerability resides in the \u003ccode\u003ecrypto_rsa_common()\u003c/code\u003e function within \u003ccode\u003elibfreerdp/crypto/crypto.c\u003c/code\u003e, where a modular-exponentiation result is written to an output buffer before a bounds check is performed, leading to out-of-bounds writes. An unauthenticated attacker can exploit this on the server side when a client attempts to connect using RDP Standard Security. By leveraging the server's published RSA public key, the attacker can forge a ciphertext whose decrypted value exceeds a fixed 32-byte buffer. This can cause a heap overflow of up to approximately 224 attacker-controlled bytes pre-authentication, leading directly to a denial of service for the FreeRDP server. The flaw was publicly disclosed on July 20, 2026.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a FreeRDP server vulnerable to CVE-2026-64620, meaning it is running FreeRDP version 3.27.1 or earlier.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates an RDP connection attempt to the target FreeRDP server.\u003c/li\u003e\n\u003cli\u003eDuring the connection handshake, the attacker forces the server to use RDP Standard Security.\u003c/li\u003e\n\u003cli\u003eThe server responds by publishing its RSA public key, which the attacker intercepts.\u003c/li\u003e\n\u003cli\u003eUsing the server's public key, the attacker crafts a malicious ciphertext designed to represent an encrypted client random value. This crafted ciphertext is specifically engineered such that its decrypted length will significantly exceed a 32-byte buffer used by the server.\u003c/li\u003e\n\u003cli\u003eThe attacker sends this specially crafted ciphertext to the FreeRDP server as part of the client random exchange.\u003c/li\u003e\n\u003cli\u003eThe server processes the client random using the vulnerable \u003ccode\u003ecrypto_rsa_common()\u003c/code\u003e function, which decrypts the value.\u003c/li\u003e\n\u003cli\u003eDuring decryption, the \u003ccode\u003eBN_bn2bin()\u003c/code\u003e function writes the result into the allocated 32-byte buffer. However, due to the missing pre-check, the decrypted value overflows this buffer by up to approximately 224 bytes with attacker-controlled data.\u003c/li\u003e\n\u003cli\u003eThis heap-based buffer overflow corrupts adjacent memory, causing the FreeRDP server process to crash, resulting in a denial of service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-64620 results in a denial of service (DoS) for the FreeRDP server. This can lead to significant operational disruption as legitimate users are unable to connect to their RDP sessions. Since the attack is pre-authentication and unauthenticated, it can be executed remotely with minimal effort, making affected servers susceptible to widespread availability issues. There are no specific victim counts or targeted sectors mentioned, but any organization using FreeRDP as a server component and exposed to the internet, or accessible by an internal attacker, is at risk of service interruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-64620 immediately by upgrading all FreeRDP installations to version 3.28.0 or later.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive logging for FreeRDP server processes and monitor for unexpected crashes or restarts, which could indicate exploitation attempts or successful denial-of-service attacks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T12:23:10Z","date_published":"2026-07-20T12:23:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-freerdp-buffer-overflow/","summary":"FreeRDP before version 3.28.0 contains a heap-based buffer overflow in the `crypto_rsa_common()` function, exploitable pre-authentication by an unauthenticated attacker crafting a malicious ciphertext to cause a denial of service on the server when a client uses RDP Standard Security.","title":"CVE-2026-64620 - FreeRDP Heap-based Buffer Overflow","url":"https://feed.craftedsignal.io/briefs/2026-07-freerdp-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - FreeRDP (\u003c=3.27.1)","version":"https://jsonfeed.org/version/1.1"}