Vulnerability Details CVE-2026-91958
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 3.6%
CVSS Severity
CVSS v3 Score 6.6
Products affected by CVE-2026-91958
-
cpe:2.3:a:freerdp:freerdp:*