CVE-2026-33985 is a heap out-of-bounds read vulnerability (ClearCodec Glyph Cache Count Desync) affecting FreeRDP versions prior to 3.24.2, which can cause pixel data from adjacent heap memory to be rendered to the screen. This Medium severity vulnerability (CVSS 5.9) has a high attack complexity and requires user interaction, but could result in a high confidentiality impact through the leakage of sensitive data. Currently, there is no evidence of active exploitation, and no public exploit code is available. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.24.2CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.