#VU125371 Double free in FreeRDP - CVE-2026-33995
Published: April 8, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to double free in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() in the Kerberos SSPI context cleanup path when handling NLA connection teardown after a failed authentication attempt. A remote attacker can trigger an authentication failure to cause a denial of service.
Only clients compiled with Kerberos support and running on systems where a Kerberos realm is configured are vulnerable.