CVE-2026-67300: FreeRDP before 3.29.0 Use-After-Free via async message proxy

Published Aug 1, 2026
·
Updated

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOWSTATEORDER and NOTIFYICONSTATEORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). The parser frees those nested buffers after the callback returns, so the queued async message later dispatches stale pointers, potentially causing memory corruption or a client crash.

Affected Software

1 affected component
FreeRDP freerdp<3.29.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.29.0
  2. Configuration

    Disable AsyncUpdate so the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER is not used, preventing stale pointers from later dispatching after the parser callback frees nested buffers.

    FreeRDP async update message proxy AsyncUpdate = disabled

Event History

Aug 1, 2026
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-67300?

CVE-2026-67300 has a high severity rating of 7.5.

2

How do I fix CVE-2026-67300?

To fix CVE-2026-67300, upgrade FreeRDP to version 3.29.0 or later.

3

What type of vulnerability is CVE-2026-67300?

CVE-2026-67300 is a use-after-free vulnerability affecting FreeRDP.

4

What systems are affected by CVE-2026-67300?

CVE-2026-67300 affects FreeRDP versions prior to 3.29.0.

5

How can an attacker exploit CVE-2026-67300?

An attacker can exploit CVE-2026-67300 by sending crafted update orders from a malicious RDP server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203