VDB

CVE-2025-68118

CVE-2025-68118 PUBLISHED CVSS 6.599999904632568 MEDIUM

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without guaranteeing NUL termination when truncation occurs. According to Microsoft documentation, `_snprintf` does not append a terminating NUL byte if the formatted output exceeds the destination buffer size. If an attacker controls the hostname value (for example via server redirection or a crafted .rdp file), the resulting filename buffer may not be NUL-terminated. Subsequent string operations performed on this buffer may read beyond the allocated memory region, resulting in a heap-based out-of-bounds read. In default configurations, the connection is typically terminated before sensitive data can be meaningfully exposed, but unintended memory read or a client crash may still occur under certain conditions. Version 3.20.0 has a patch for the issue.

EPSS 0.06% · 18.3th percentile

Risk Scores

CVSS v4.0
6.599999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
EPSS Score
0.06%
18.3th percentile

Affected Products

VendorProductVersions
FreeRDPFreeRDP< 3.20.0
freerdpfreerdp0

Timeline

  • Dec 15, 2025 CVE ID Reserved
  • Dec 17, 2025 CVE Published
  • Dec 18, 2025 EPSS Score
  • Dec 18, 2025 CVE Updated
  • Dec 22, 2025 EPSS Score
  • Dec 26, 2025 EPSS Score
  • Dec 30, 2025 EPSS Score
  • Jan 2, 2026 EPSS Score
  • Jan 6, 2026 EPSS Score
  • Jan 10, 2026 EPSS Score
  • Jan 14, 2026 EPSS Score
  • Jan 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›