SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64621

HIGH · CVSS 7.3 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

FreeRDP versions prior to 3.28.0 are vulnerable to a double-free vulnerability when handling the selectedmonitors field in .rdp connection files. This flaw allows an attacker to exploit a crafted .rdp file, potentially leading to arbitrary code execution or application crashes. Organizations using FreeRDP, especially those relying on remote desktop functionalities, should prioritize patching to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64621
Severity
HIGH
CVSS
7.3
EPSS
0.30%

Original NVD Description

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.

Related CVEs

Other vulnerabilities affecting the same vendor(s)