FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-15 17:17
NVD link : CVE-2026-91958
Mitre link : CVE-2026-91958
CVE.ORG link : CVE-2026-91958
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
