CVE-2026-91958
EUVD-2026-7863415.09.2026, 16:17
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| freerdp | freerdp | 3.11.0 ≤ 𝑥 < 3.31.0 | CNA |
Debian Releases
Common Weakness Enumeration