Impact
FreeRDP versions prior to 3.29.0 contain a resource exhaustion flaw that allows an attacker to send oversized chunked HTTP responses, causing the client to consume memory until the configured size limit is reached, which can lead to application crashes and denial of service.
Affected Systems
Multiple builds of the FreeRDP client shipped by the FreeRDP project, all versions earlier than 3.29.0.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. EPSS data are unavailable, but the weakness remains serious where clients talk to an RD Gateway that the attacker can control. The flaw is listed as not yet in the CISA KEV catalog. Attackers would need network access to a malicious RD Gateway endpoint to feed oversized chunked HTTP responses to the client in order to exhaust its memory resources.
OpenCVE Enrichment