FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
History

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Freerdp
Freerdp freerdp
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 31 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
Title FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read
Weaknesses CWE-125
CWE-131
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-31T18:53:29.979Z

Reserved: 2026-03-24T22:20:06.211Z

Link: CVE-2026-33985

cve-icon Vulnrichment

Updated: 2026-03-31T18:50:33.418Z

cve-icon NVD

Status : Received

Published: 2026-03-30T22:16:19.720

Modified: 2026-03-30T22:16:19.720

Link: CVE-2026-33985

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-30T21:43:13Z

Links: CVE-2026-33985 - Bugzilla