CVE-2026-72745 | FreeRDP up to 3.29.x Kerberos kerberos.c kerberos_DecryptMessage out-of-bounds

SecurityVulns

A vulnerability labeled as critical has been found in FreeRDP up to 3.29.x. Affected is the function kerberos_DecryptMessage of the file winpr/libwinpr/sspi/Kerberos/kerberos.c of the component Kerberos. Executing a manipulation can lead to out-of-bounds read.

This vulnerability is registered as CVE-2026-72745. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More