Impact
A heap‑based buffer overflow occurs in FreeRDP clients that use TS Gateway when the server advertises an unbounded max_xmit_frag value. The client copies a response fragment of up to 65535 bytes into a 4088‑byte receive buffer, causing a crash and providing an opportunity for an attacker to corrupt heap state and potentially execute arbitrary code. The issue was addressed in FreeRDP 3.27.0, which bounds max_xmit_frag to the buffer size.
Affected Systems
Affected systems are FreeRDP client installations running any version earlier than 3.27.0 that are configured to communicate through a TS Gateway server. The vulnerability is triggered by a malicious gateway that sends an oversized fragment, so any client that connects to such a gateway is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS score of < 1% indicates a very low probability of exploitation, and the lack of listing in the CISA KEV catalog means no publicly disclosed exploits are currently tracked. The attack requires the attacker to operate a rogue TS Gateway and send a large fragment to a client, so a remote binary exploitation vector exists, with high risk if the client trusts an untrusted gateway.
OpenCVE Enrichment
Ubuntu USN