Impact
A flaw in the FreeRDP server’s RDPECAM camera device enumerator channel allows a malicious RDP client to supply an unterminated DeviceName or VirtualChannelName string. The server scans these fields for a NUL terminator, then dereferences once past the bound,‑to‑ 2‑byte out‑of‑bounds heap read (CWE‑125). This oversight can expose sensitive data stored on the heap but does not provide direct code execution or denial of service; the impact is limited to information disclosure.
Affected Systems
Any FreeRDP server running a version earlier than 3.28.0 with the MS‑RDPECAM camera device enumerator channel enabled is vulnerable. The issue is remedied in FreeRDP.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must establish an RDP session and send a crafted request to the enumerator channel. The attack vector is remote, and it is inferred that authenticated or unfiltered RDP client access might be required. Given these conditions, the overall risk is moderate, with a lower likelihood of exploitation in environments where RDP access is tightly controlled.
OpenCVE Enrichment