SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64620

CRITICAL · CVSS 9.8 EPSS 0.85% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

FreeRDP versions prior to 3.28.0 are vulnerable to a heap-based buffer overflow in the crypto_rsa_common() function, which allows unauthenticated attackers to exploit the flaw by sending specially crafted ciphertexts. This can lead to a denial of service due to the overflow of a fixed 32-byte buffer, potentially allowing attackers to write up to 224 bytes of controlled data. Organizations using affected versions of FreeRDP should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64620
Severity
CRITICAL
CVSS
9.8
EPSS
0.85%

Original NVD Description

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)