SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-57157

MEDIUM · CVSS 6.5 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

FreeRDP server implementations prior to version 3.28.0 are vulnerable to an out-of-bounds heap read due to improper handling of attacker-supplied fields in the MS-RDPECAM camera device enumerator channel. This vulnerability could allow a malicious RDP client to exploit the flaw, potentially leading to information disclosure. Organizations using FreeRDP for remote desktop services should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57157
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%

Original NVD Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL terminator in channels/rdpecam/server/camera_device_enumerator_main.c and then dereference once past the scan bound, allowing a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. This issue is fixed in version 3.28.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)