Description
FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Read leading to Process Abort
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a buffer over-read in the rts_read_result function of the RPC gateway transport parser. An attacker can send a maliciously crafted BIND_ACK Protocol Data Unit with a truncated result entry, causing the process to read beyond allocated memory bounds and abort. This out-of-bounds access can lead to a denial of service by crashing the FreeRDP client process.

Affected Systems

All FreeRDP installations with a version prior to 3.31.0 are affected. The flaw is present inDP product without an explicit patch level or build qualifier. Users should verify if they are running an older release than 3.31.0.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level. The EPSS score of < 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a remote network attacker targeting the RPC gateway transport; the attacker must be able to deliver a crafted BIND_ACK PDU to the vulnerable server or client, but no further authentication or privileged access is required. The attack can disrupt service by causing the target application to terminate.

Generated by OpenCVE AI on September 20, 2026 at 16:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to FreeRDP 3.31.0 or later, which includes the fix for the buffer over-read in rts_read_result.
  • If upgrading is not immediately possible, review configuration to disable the RPC gateway transport or restrict it to trusted networks, reducing exposure to the malicious B controls such as firewall rules to filter or block unexpected BIND_ACK PDUs or limit access to the port used by the RPC gateway.
  • Enable logging and monitoring for the RPC gateway to detect unexpected BIND_ACK packets and promptly investigate any abnormal activity.

Generated by OpenCVE AI on September 20, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.
Title FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-125
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:29.503Z

Reserved: 2026-09-15T11:08:44.669Z

Link: CVE-2026-91959

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:26.396Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:50.930

Modified: 2026-09-24T12:17:19.670

Link: CVE-2026-91959

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:13Z

Links: CVE-2026-91959 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses