#VU125361 Heap-based buffer overflow in FreeRDP - CVE-2026-31806
Published: April 8, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in nsc_process_message() when processing SURFACE_BITS_COMMAND messages using NSCodec. A remote attacker can send a specially crafted RDP server message with oversized bitmap dimensions to execute arbitrary code.
The issue can be triggered when a FreeRDP client connects to a malicious RDP server.