CVE-2026-64620: FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in cryptorsacommon() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BNbn2bin() and only afterward checks outputlength > outlength, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDP (libfreerdp)to a version that resolves this vulnerability.Fixed in 3.28.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64620?
The severity of CVE-2026-64620 is critical with a score of 9.8.
What is the impact of CVE-2026-64620?
CVE-2026-64620 can lead to a heap-based buffer overflow that may allow an attacker to execute arbitrary code.
How do I fix CVE-2026-64620?
To fix CVE-2026-64620, upgrade to FreeRDP version 3.28.0 or later.
Which versions of FreeRDP are affected by CVE-2026-64620?
FreeRDP versions prior to 3.28.0, specifically up to 3.27.1, are affected by CVE-2026-64620.
What component of FreeRDP is vulnerable in CVE-2026-64620?
CVE-2026-64620 affects the crypto_rsa_common() function in the libfreerdp/crypto/crypto.c file.