Impact
FreeRDP implementations before version 3.31.0 transmit stale heap data during the Save Session Info procedure because reserved padding is sought rather than zeroed, leaving residual memory in outbound packets. This flaw can expose server or proxy memory contents, including cleartext credentials from previous sessions, to a remote RDP client, resulting in a confidentiality breach.
Affected Systems
Systems based on the FreeRDP library running versions 3.0.0 through 3.30.0 are affected. The vulnerability applies to both server-side components that use rdpUpdate::SaveSessionInfo and to the freerdp-proxy tool that forwards these PDUs between the server and a downstream client.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high severity risk of information disclosure. Because the EPSS score is not available, the likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Attackers who can establish a Remote Desktop session to a vulnerable FreeRDP server can capture the leaked heap payload in the outgoing Save Session Info PDUs, potentially retrieving prior session credentials.
OpenCVE Enrichment