216.73.216.197

CVE-2026-23948

· Published 09/02/2026 19:15 · Modified 10/02/2026 15:09

Labels: CVE-2026-23948 2026-02-09CVE-2026-23948CWE-476[email protected]

Essential information

Published
09/02/2026 19:15
Modified
10/02/2026 15:09
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or cbUserName=0. This vulnerability is fixed in 3.22.0.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
freerdp / freerdp cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

References