CVE-2026-33985
published 2026-03-30CVE-2026-33985: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen…
PriorityP434high7.1CVSS 3.1
AVNACLPRNUIRSUCHINAL
EPSS
0.21%
10.7th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.24.2+dfsg-1 (forky) | freerdp3 3.24.2+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.24.2+dfsg-1 (forky) | freerdp3 3.24.2+dfsg-1 (forky) |
| freerdp | freerdp | < 3.24.2 | 3.24.2 |
| ubuntu | freerdp3 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
osv7.1HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-07-20
CVE-2026-33995 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
vendor_redhat·2026-03-30·CVSS 5.9
CVE-2026-33985 [MEDIUM] CWE-125 FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A remote attacker could exploit a vulnerability where pixel data from adjacent heap memory is rendered to the screen. This can lead to the disclosure of sensitive data to the attacker.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to w
Debian
CVE-2026-33985: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
vendor_debian·2026·CVSS 5.9
CVE-2026-33985 [MEDIUM] CVE-2026-33985: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
Scope: local
bookworm: open
bullseye: open
OSV
CVE-2026-33985: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-03-30·CVSS 7.1
CVE-2026-33985 [HIGH] CVE-2026-33985: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33985 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-33985 [MEDIUM] CVE-2026-33985 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33985 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
Source : NVD
## 7.1
Score
Published March 30, 2026
Severity HIGH
CNA Score 5.9
Affected Technologies
NixOS
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
freerdp
freerdp-devel
Sources
NVD
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 29, 2026
Chainguard Has Fix Added at: Mar 31, 2026
Bugzilla
CVE-2026-33985 FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
bugzilla·2026-03-30·CVSS 7.1
CVE-2026-33985 [HIGH] CVE-2026-33985 FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
CVE-2026-33985 FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:16014 https://access.redhat.com/errata/RHSA-2026:16014
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:16019 https://access.redhat.com/errata/RHSA-2026:16019
2026-03-30
Published