CVE-2026-73242
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-122
Not enough EPSS history yet.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713318.1 HIG—
———Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.9hCVE-2026-703477.8 HIG—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.5hCVE-2026-703457.8 HIG—
———Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.5hCVE-2026-703306.7 MED—
———Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.5hCVE-2026-703046.7 MED—
———Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.5hCVE-2026-701308.4 HIG—
———Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.8h