Beveiligingsadvies

CVE-2026-91958

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 15:18:13
Laatst bijgewerkt 2026-09-15 15:59:22
Toegewezen door VulnCheck
CVSS-score 6.9
Status PUBLISHED

Beschrijving

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.