What is CVE-2026-67299?
A client-side heap use-after-free vulnerability exists in FreeRDP versions before 3.29.0, triggered during processing of WINDOW_ICON_ORDER messages when AsyncUpdate is enabled. This flaw could allow remote code execution, and users are advised to update to FreeRDP 3.29.0 or later.
Azərbaycanca: FreeRDP 3.29.0-dan əvvəlki versiyalarda müştəri tərəfində "heap use-after-free" zəifliyi aşkarlanıb. Xüsusilə "AsyncUpdate" aktiv olduqda "WINDOW_ICON_ORDER" mesajlarının işlənməsi zamanı yaranan bu boşluq, uzaqdan kod icrasına səbəb ola bilər. İstifadəçilərə FreeRDP-ni 3.29.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: FreeRDP
FAQ2
What software is affected by CVE-2026-67299?
FreeRDP.
What version of FreeRDP is recommended to fix this vulnerability?
3.29.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.