securityonline.info 9/2/2026, 1:36:42 AM · external

FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server

FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server
CyberSIXT Evidence Panel
Primary Source github.com

TWO critical vulnerabilities in FreeRDP version 3.31.0 have been identified: an authentication bypass and a remote code execution (RCE) exploit. The patched version addresses five server-role flaws, with potential impacts on various Linux remote desktop tools. The authentication bypass allows unauthorized access by manipulating socket responses. Other issues include memory leaks and a use-after-free bug, mainly leading to denial of service.

Upgrading to version 3.31.0 is highly recommended, while older versions remain at risk, especially for RDP server deployments. Full-chain exposure is currently limited, with no confirmed real-world exploits.

View Primary Source Via securityonline.info

Article by CyberSIXT