What is CVE-2026-67300?
FreeRDP versions before 3.29.0 contain a heap use-after-free vulnerability in the async update message proxy when processing RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER with AsyncUpdate enabled. This affects client-side installations and could allow code execution via a malicious RDP server; users should upgrade immediately.
Azərbaycanca: FreeRDP-nin 3.29.0-dən əvvəlki versiyalarında AsyncUpdate aktiv olduqda, RDP serverindən gələn spesifik yeniləmə mesajlarının işlənməsi zamanı heap use-after-free zəifliyi mövcuddur. Bu, uzaq masaüstü bağlantıları istifadə edən istifadəçilərə təsir edir və zərərli server kod icrasına səbəb ola bilər; istifadəçilər dərhal son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: FreeRDP
FAQ2
Which versions of FreeRDP are affected by CVE-2026-67300?
This heap use-after-free vulnerability affects FreeRDP versions before 3.29.0.
What should I do to protect against CVE-2026-67300?
Users should immediately upgrade to the latest version of FreeRDP (3.29.0 or newer).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.