MEDIUM 6.9 NVD
CVE-2026-91958
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monito
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r
- https://www.vulncheck.com/advisories/freerdp-3.11.0-through-3.30.0-heap-buffer-overflow-vi
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.