7.1
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
Basic Information
ID
CVE-2026-33982
Source
GitHub_M
Published
Mar 30, 2026 at 21:42
Modified
Mar 31, 2026 at 14:07
Affected Product
Vendor
FreeRDP
Product
FreeRDP
Version
< 3.24.2
Affected Versions
FreeRDP FreeRDP < 3.24.2