Impact
The FreeRDP server prior to version 3.31.0 contains a use‑after‑free flaw in its DRDYNVC parser. Authenticated clients can race AUDIN channel‑closure notifications against the parsing of DRDYNVC data so that the server dereferences a channel pointer after the associated synchronization lock has been released. This produces heap‑memory corruption that could allow an attacker to execute arbitrary code on the server.
Affected Systems
FreeRDP server (product name FreeRDP) running any version older than 3.31.0 is vulnerable. The issue is confined to the server side of the Remote Desktop Protocol implementation and only applies to installations that enable DRDYNVC channel support.
Risk and Exploitability
The vulnerability receives a CVSS score of 7.7, indicating high severity. An EPSS score below 1% indicates a low but non‑zero probability that the flaw will be exploited. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated RDP session and careful timing of channel‑closure events, meaning the attacker must be able to interact with the server over RDP and trigger the race condition to corrupt heap memory.
OpenCVE Enrichment