Description
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds heap read/write access
Action: Patch ASAP
AI Analysis

Impact

FreeRDP versions before 3.31.0 lack proper bounds validation for MonitorIds array values when parsing RDP connection files, which can lead to unbounded array indexing in the xf_detect_monitors function. This flaw permits attackers to craft a malicious .rdp file containing an out-of-range selectedmonitors value, resulting in an out-of-bounds heap read and write operation during execution of xfreerdp. The vulnerability could potentially corrupt memory, leading to information disclosure or execution of arbitrary code, as it represents a classic out-of-bounds buffer overflow (CWE-125 and CWE-787).

Affected Systems

The issue affects FreeRDP deployments on all platforms running versions 3.11.0 through 3.30.0. Systems that include the xfreerdp client and parse untrusted RDP files are susceptible. Upgrading to 3.31.0 or newer removes the vulnerability.

Risk and Exploitability

The CVSS score of 6.9 combined with an EPSS score of 0.00199 indicates a low but non-zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker providing a crafted .rdp file to a user who then opens it with xfreerdp, possibly enabling an attacker to read or corrupt application memory. The design of the flaw allows local file-based exploitation, so users who handle untrusted RDP files are at the highest risk.

Generated by OpenCVE AI on September 20, 2026 at 16:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update FreeRDP to version 3.31.0 or later, which implements bounds checks on MonitorIds array values.
  • If an immediate upgrade is not feasible, isolate the xfreerdp process in a controlled environment and restrict the source of .rdp files that can be opened, ensuring only authenticated and trusted files are processed.
  • Monitor application logs for abnormal memory access patterns or crashes that may indicate exploitation attempts, and apply additional defensive measures such as application whitelisting or sandboxing for X/Freerdp.

Generated by OpenCVE AI on September 20, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
Title FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-125
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:59:22.785Z

Reserved: 2026-09-15T11:07:34.399Z

Link: CVE-2026-91958

cve-icon Vulnrichment

Updated: 2026-09-15T15:59:18.157Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:50.787

Modified: 2026-09-24T12:17:14.823

Link: CVE-2026-91958

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:13Z

Links: CVE-2026-91958 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses