FreeRDP update patches 22 security flaws across media and crypto paths
FreeRDP has released version 3.29.0 to address 22 security advisories, including critical hardening for AV1 and H.264 decoder outputs. This maintenance update impacts the numerous downstream workstation and server tools that rely on the open-source RDP implementation.
Key Takeaways
- Fixes include critical bounds and length checks for AV1 and H.264 decoders to prevent output overflows.
- The core now rejects short server random values during initial RDP key establishment to strengthen encryption.
- Update adds support for endpoint FedAuth token authentication and resolves X.509 certificate null-byte vulnerabilities.
- Version 3.29.0 arrived just one week after the feature-heavy 3.28.0 release, which added a server-side smartcard API.
Why It Matters
As a foundational open-source implementation of the Remote Desktop Protocol, FreeRDP is embedded in dozens of downstream workstation and server tools. Vulnerabilities in its media decoders could allow remote code execution through malicious video streams, a high-stakes risk for media production and remote editing environments. This rapid patching cycle underscores the project's strategy to address academic and researcher audits immediately before flaws are weaponized at scale. Stakeholders should prioritize deployment to protect internal RDP gateways from lateral movement. Watch for the official CVE scoring for these 22 flaws to determine which require immediate emergency patching versus staggered maintenance.
Additional Context
The urgency behind FreeRDP’s current security cycle reflects a broader trend of Intensified targeting of remote access protocols. In mid-2025, security researchers identified CVE-2025-48817, a critical path-traversal flaw in Microsoft’s native Remote Desktop Client with a CVSS score of 8.8. This vulnerability demonstrated how unauthenticated attackers could execute arbitrary code simply by luring a user to connect to a malicious server, highlighting the risks inherent in the file-transfer and clipboard negotiation phases of the protocol. Furthermore, recent research from Forescout Technologies in May 2026 revealed that approximately 1.8 million RDP servers remain directly exposed to the internet, with manufacturing and retail sectors showing the highest levels of vulnerability. This exposure is compounded by the fact that nearly 18% of these servers run end-of-life operating systems that no longer receive official patches. These figures highlight the critical role that a well-maintained open-source library like FreeRDP plays in the broader ecosystem, as it often provides the security backbone for administrators seeking an alternative to legacy or deprecated proprietary systems. The inclusion of media-specific hardening for AV1 and H.264 in version 3.29.0 also aligns with the protocol's 2025 shift toward GPU-accelerated rich media support. Per reports from RDS-Tools in May 2025, the industry-wide push for zero-trust architecture and 4K remote rendering has made the RDP media stack a primary attack surface. By resolving surface dimension mismatches and region rectangle checks now, FreeRDP maintainers are addressing flaws that could otherwise allow attackers to exploit the very hardware-acceleration features designed to improve remote streaming performance.
Read full article at helpnetsecurity.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source