CVE-2026-25952 | FreeRDP up to 3.22.x xf_SetWindowMinMaxInfo use after free (GHSA-cgqm-cwjg-7w9x / Nessus ID 300191)
A vulnerability, which was classified as critical, has been found in FreeRDP up to 3.22.x. The affected element is the function xf_SetWindowMinMaxInfo. Performing a manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-25952. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.