CyberRota Analysis
AI-GeneratedFreeRDP versions prior to 3.30.0 are vulnerable to an out-of-bounds error in the kerberos_DecryptMessage() function, which allows a malicious peer to exploit the EC field of a GSS Wrap token during CredSSP/NLA authentication. This vulnerability can lead to information disclosure, memory corruption, or denial of service due to improper bounds checking in pointer arithmetic. Organizations using FreeRDP should prioritize patching this vulnerability to mitigate potential security risks.
CVE
CVE-2026-72745
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Original NVD Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.