Impact
FreeRDP versions before 3.29.0 contain a reachable assertion in the serial device handling code that triggers when a server sends an unsupported IOCTL request with an incorrect output buffer length. The assertion compares the expected output length to the actual return value; a mismatch causes the client to abort and terminate, resulting in a denial of service. The weakness is a flawed assumption shown by CWE-617, leading to client crash when invalid data is processed.
Affected Systems
The affected product is FreeRDP, a remote desktop protocol client. All releases prior to 3.29.0 are vulnerable when serial device redirection is enabled. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no public exploit is known. The likely attack vector is from a remote RDP server that can send a crafted device control request to a FreeRDP client with serial redirection enabled; this inference is based on the description of the trigger conditions.
OpenCVE Enrichment