← back
CVE-2026-33985

FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read

CVSS 5.9 MEDIUMEPSS 0.2%CWE-125CWE-131
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
Affected products
FreeRDP · FreeRDP

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →