Description
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Client Crash
Action: Patch
AI Analysis

Impact

FreeRDP versions prior to 3.31.0 have a null pointer dereference in the gdi_surface_bits function when handling Surface Bits commands that specify the NSCodec codec. The bug allows a malicious RDP server to send a crafted command that triggers the dereference, causing the client process to crash. The crash denies service to the user and can be repeated, but it does not provide code execution or privilege escalation.

Affected Systems

All installations of FreeRDP that are older than version 3.31.0 are vulnerable regardless of whether NSCodec is enabled. The vulnerability affects the client side of the Remote Desktop Protocol and is mitigated by using a patched release.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity moderate risk. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation. FreeRDP clients can be targeted only by an attacker who controls or can impersonate an RDP server, which may require privileged network access or social engineering. Because the vulnerability is triggered by a crafted command, an active attacker with networking access to the client can cause repeated service interruptions. The vulnerability is not listed in the CISA KEV catalog, indicating that no known commercial exploitation campaigns have been observed yet.

Generated by OpenCVE AI on September 20, 2026 at 16:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the FreeRDP client to version 3.31.0 or later to apply the vendor‑supplied fix.
  • If an immediate upgrade is impossible, restrict RDP traffic to trusted servers to reduce exposure.
  • Implement a patch‑management policy that ensures all Remote Desktop clients receive timely updates, and monitor client logs for unexpected crashes that may indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
Title FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-476
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:28:25.591Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91954

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:30.917Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:49.807

Modified: 2026-09-24T12:16:39.400

Link: CVE-2026-91954

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:10Z

Links: CVE-2026-91954 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses