Impact
FreeRDP versions earlier than 3.31.0 contain a flaw in the RDPGFX server’s ResetGraphics PDU serializer where padding bytes in a fixed 340‑byte wire format are not initialized. This oversight allows an attacker to read uninitialized heap memory, exposing live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR by revealing the GLib module base address, effectively leaking sensitive runtime information.
Affected Systems
Any installation of FreeRDP using a version lower than 3.31.0 is vulnerable. The flaw applies to the RDPGFX component of the server deployments that accept RDP connections and run these earlier releases are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity with potential for significant impact if an attacker can send crafted RDP packets to the server. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KE exploits at the time of this assessment. Attackers would need the ability to communicate with the target’s RDP service, which is typically exposed; if they can do so, they could undermine ASLR and potentially leverage the leaked pointers for further exploitation, making it a tangible risk for systems exposing FreeRDP services.
OpenCVE Enrichment