Impact
FreeRDP versions before 3.31.0 contain an out‑of‑bounds read in the smartcard ATR decoder that does not validate the length field of the ATR against the size of a fixed inline array. An attacker who can send an RDP packet that includes a PAKID_CORE_DEVICE_IOCOMPLETION response with an oversized ATR length can cause the decoder to read past the bounds of the array. The read occurs on the stack or heap and results in process termination, which can be used to crash the RDP client or impair service availability. The weakness is classified as CWE‑125, an out‑of‑bounds read.
Affected Systems
All FreeRDP clients whose installed version is earlier than 3.31.0 are affected. This includes any system using the up‑to‑date open‑source RDP client distributions that have not applied the 3.31.0 release or later.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability; however, because the vulnerability requires an authenticated client context, an attacker would need network access to the target RDP session or the ability to inject crafted packets. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit is known, but the nature of the fault allows a crash, which can be leveraged for denial of service or to pivot to further attacks if the application is compromised. The likely attack vector is a malicious RDP client that can send custom PAKID_CORE_DEVICE_IOCOMPLETION packets.
OpenCVE Enrichment