Impact
FreeRDP versions prior to 3.31.0 include an out‑of‑bounds write in the server‑side static virtual channel handler when the AUTHENTICATED clients can send oversized channel messages that trigger a buffer underflow, corrupting heap memory and altering live pointers. This memory corruption creates the potential for arbitrary code execution by the attacker.
Affected Systems
The vulnerability affects all FreeRDP releases before 3.31.0. It is specific to the FreeRDP:FreeRDP product family and impacts any system running an affected DP client/server library.
Risk and Exploitability
With a CVSS score of 7.7 the flaw is classified as high severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog; it requires authenticated clients, making it a remote threat that requires valid user credentials or elevated client access. No public exploitation information is currently available, yet the high severity places this vulnerability on the top of the risk list for affected deployments.
OpenCVE Enrichment