Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-91958

MEDIUM NVD
CVSS Score 6.6
Severity MEDIUM
Published Sep 15, 2026
Vendor unknown

Description

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

References