Impact
FreeRDP versions earlier than 3.31.0 contain an out‑of‑bounds read in the rdpdr_dump_packet routine. The flaw arises from a 32‑bit unsigned integer wraparound in buffer bounds validation. A crafted RDPDR packet with a computerNameLen value close to the maximum unsigned 32‑bit value can bypass the bounds check, allowing the client to read memory beyond the packet buffer. This may result in client crashes or the disclosure of heap contents in out‑of‑bounds read (CWE‑125).
Affected Systems
The affected product is FreeRDP (FreeRDP). All releases prior to version 3.31.0 are impacted. No specific sub‑versions are mentioned, so the entire pre‑3.31.0 series is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests that the likelihood of public exploitation is low at present. The vulnerability is not listed in CISA KEV, indicating no current known exploits. However, the flaw can be triggered remotely by a malicious RDP server that sends a specially crafted RDPDR packet, which would force the client to crash or leak sensitive data from the client’s heap.
OpenCVE Enrichment