What is CVE-2026-67301?
CVE-2026-67301 is an out-of-bounds read vulnerability in FreeRDP before version 3.29.0, specifically in the async update message proxy for PolygonSC and PolygonCB drawing orders. This issue is exploitable when AsyncUpdate is enabled (e.g., via /async-update). Users should upgrade to FreeRDP 3.29.0 or later immediately.
Azərbaycanca: CVE-2026-67301, FreeRDP-nin 3.29.0-dan əvvəlki versiyalarında async yeniləmə mesajı proxy-də PolygonSC və PolygonCB əmrləri zamanı baş verən out-of-bounds read zəifliyidir. Xüsusilə `/async-update` parametri aktiv olduqda bu boşluq istismar edilə bilər. İstifadəçilər dərhal FreeRDP-ni 3.29.0 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-125; shared vendor: FreeRDP
FAQ2
Which versions of FreeRDP are affected by CVE-2026-67301?
This out-of-bounds read vulnerability affects FreeRDP versions before 3.29.0.
What should users do to protect against CVE-2026-67301?
Users should immediately upgrade FreeRDP to version 3.29.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.