CVE-2026-68579: FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read

Published Aug 2, 2026
·
Updated

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStreamRead function (client/Windows/wfcliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStreamRead requests file contents from the RDP server and then copies the response into the caller's buffer using the server-supplied length (reqfsize) instead of cb. A malicious or compromised RDP server can return an oversized CBFILECONTENTSRESPONSE, causing an out-of-bounds write of attacker-controlled data into the paste consumer's heap buffer when a user pastes server-offered clipboard file contents.

Affected Software

1 affected component
FreeRDP freerdp<=3.29.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.30.0
  2. Compensating control

    Mitigate exposure by preventing untrusted RDP servers from being used for clipboard file content (e.g., restrict RDP connectivity so users can only connect to approved/trusted RDP hosts).

Event History

Aug 2, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68579?

CVE-2026-68579 has a critical severity rating of 9.6.

2

What type of vulnerability is CVE-2026-68579?

CVE-2026-68579 is a heap-based buffer overflow vulnerability.

3

How do I fix CVE-2026-68579?

To fix CVE-2026-68579, upgrade to FreeRDP version 3.30.0 or later.

4

What affected software is associated with CVE-2026-68579?

FreeRDP versions up to 3.29.0 are affected by CVE-2026-68579.

5

What could be the impact of exploiting CVE-2026-68579?

Exploitation of CVE-2026-68579 could lead to code execution and compromise system integrity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203