CVE-2026-91958

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 16:17

Updated : 2026-09-15 17:17


NVD link : CVE-2026-91958

Mitre link : CVE-2026-91958

CVE.ORG link : CVE-2026-91958


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read