LOWVulnerability

CVE-2026-67305

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation.

Properties

cve_id
CVE-2026-67305
published_at
2026-08-01T13:17:00.113
last_modified
2026-08-05T14:17:09.637

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67305 — Ninja Signal Threat Intelligence | Ninja Signal