CVE-2026-72745: FreeRDP before 3.30.0 Out-of-Bounds Read via Kerberos GSS Wrap-token EC
Published Aug 11, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.
Affected Software
1 affected component
FreeRDP freerdp<3.30.0
Event History
Aug 11, 2026
CVE Published
via MITRE·12:16 PM
Rejected
via MITRE·12:16 PM
Data Sourced
via NVD·01:19 PM
Description
Aug 12, 2026
Rejected
via MITRE·04:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-72745?
CVE-2026-72745 has a severity rating of high with a score of 7.5.
2
How do I fix CVE-2026-72745?
To fix CVE-2026-72745, upgrade FreeRDP to version 3.30.0 or later.
3
What types of attacks are possible with CVE-2026-72745?
CVE-2026-72745 can be exploited to perform out-of-bounds read attacks affecting data integrity.
4
Is my system vulnerable if I use FreeRDP before version 3.30.0 for Kerberos authentication?
Yes, systems using FreeRDP before version 3.30.0 for Kerberos authentication are vulnerable to CVE-2026-72745.
5
What components of FreeRDP are affected by CVE-2026-72745?
CVE-2026-72745 affects the kerberos_DecryptMessage function located in the kerberos.c file.