LOWVulnerability

CVE-2026-73242

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.

Properties

epss_score
0.0035
cve_id
CVE-2026-73242
published_at
2026-08-11T20:18:49.260
last_modified
2026-09-09T20:50:00.950
epss_percentile
0.28207

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73242 — Ninja Signal Threat Intelligence | Ninja Signal