CVE-2025-68118: Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function freerdpcertificatedatahash uses the Microsoft-specific snprintf function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, snprintf does not append a terminating NUL byte if the formatted output exceeds the destination buffer size. If an attacker controls the hostname value (for example via server redirection or a crafted .rdp file), the resulting filename buffer may not be NUL-terminated. Subsequent string operations performed on this buffer may read beyond the allocated memory region, resulting in a heap-based out-of-bounds read. In default configurations, the connection is typically terminated before sensitive data can be meaningfully exposed, but unintended memory read or a client crash may still occur under certain conditions. Version 3.20.0 has a patch for the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68118?
CVE-2025-68118 has a high severity rating due to its impact on certificate handling which can lead to exploitation on Windows platforms.
How do I fix CVE-2025-68118?
To fix CVE-2025-68118, upgrade FreeRDP to version 3.20.0 or later, which addresses the vulnerability in certificate handling.
What systems are affected by CVE-2025-68118?
CVE-2025-68118 affects FreeRDP versions prior to 3.20.0 on Windows platforms.
What types of attacks can CVE-2025-68118 facilitate?
CVE-2025-68118 can facilitate man-in-the-middle attacks due to improper handling of certificates.
Is there a workaround for CVE-2025-68118 until I can update?
There is no official workaround for CVE-2025-68118, so upgrading to a patched version is essential.