CVE-2026-91958
MEDIUM
NVD
CVSS Score
6.6
Severity
MEDIUM
Published
Sep 15, 2026
Vendor
unknown
Description
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.