Impact
FreeRDP before version 3.29.0 contains a heap read vulnerability in the UVC H.264 extension-unit parser. The parser fails to validate the descriptor length before accessing the GUID field, allowing a local attacker who controls a malicious USB video camera to trigger a read beyond the allocated buffer during camera stream setup. The resulting out‑of‑bounds heap read can cause the FreeRDP client to crash, leading to a denial of service. The weakness is identified as CWE‑125.
Affected Systems
The affected product is FreeRDP. All installations of FreeRDP with a version earlier than 3.29.0 are impacted. Upgrading to 3.29.0 or later removes the vulnerability.
Risk and Exploitability
The CVSS score is 2.4, indicating a low‑severity flaw. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires local access to the target and a malicious USB video camera. Because the attack is local, the likelihood is limited to environments where users can plug in USB devices, but any successful exploit will lead to a crash of the FreeRDP client, denying remote desktop functionality.
OpenCVE Enrichment