Vulnerability Description
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r
- https://www.vulncheck.com/advisories/freerdp-3.11.0-through-3.30.0-heap-buffer-o
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r
FAQ
What is CVE-2026-91958?
CVE-2026-91958 is a vulnerability with a CVSS score of 6.6 (MEDIUM). FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP ...
How severe is CVE-2026-91958?
CVE-2026-91958 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91958?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.