Impact
FreeRDP versions prior to 3.31.0 contain an out-of-bounds write in the urbdrc client channel’s urb_send_current_frame_number_result() function. A malicious Remote Desktop Protocol server can craft a 28-byte USB redirection message that forces the client to write 4 bytes beyond a 16-byte buffer, causing the client to crash when verbose assertions are enabled. The result is a denial of service against the user of the FreeRDP client. The flaw is a classic instance of memory corruption (CWE-617 and CWE-787).
Affected Systems
The affected software is FreeRDP, distributed under the name FreeRDP. All releases from version 3.14.0 up to and including 3.30.0 are vulnerable. Users running any of those releases remain exposed until they upgrade to 3.31.0 or later.
Risk and Exploitability
The base CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1 % reflects a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. To exploit the flaw an attacker must control or compromise an RDP server and send a specially crafted USB redirection packet to a vulnerable client over the network. The observable effect is a crash of the FreeRDP client when verbose assertions are on, resulting in a temporary service interruption.
OpenCVE Enrichment