Impact
In FreeRDP versions 3.28.0 and earlier, the planar RLE bitmap decoder fails to validate the number of raw bytes after a control byte, resulting in an out-of-bounds read when a server sends a truncated planar-encoded bitmap or surface update. The flaw can cause the client to crash or leak internal memory contents, potentially exposing sensitive data or delivering a denial‑of‑service. It is classified as CWE‑125.
Affected Systems
FreeRDP up to and including version 3.28.0 is affected. Users running any build of the FreeRDP client older than version 3.29.0 that may accept bitmap updates or RDPGFX surface commands from remote RDP servers are potentially impacted.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability carries a moderate risk. No EPSS data is available and the issue is not listed in the CISA KEV catalog. The attack vector is remote: a malicious or compromised RDP server can send malformed planar data to a client. Because the flaw only triggers an out‑of‑bounds read, exploitation is unlikely to yield code execution but could trigger crashes or memory disclosures, enabling denial‑of‑service or partial data exposure.
OpenCVE Enrichment