A vulnerability has been found in FreeRDP up to 3.28.x and classified as problematic. This affects the function
update_message_WindowIcon of the component Async Update Message Proxy. This manipulation of the argument iconInfo causes use after free.
This vulnerability is registered as CVE-2026-67299. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.