Impact
FreeRDP versions before 3.31.0 have a flaw in the pool_decode_rect function that causes an infinite loop when decoding AVC444 metablocks containing more region rectangles than the size of a pre‑allocated worker array. A malicious RDP server can send crafted graphics updates that exhaust CPU resources, causing the client to hang. The flaw involves insufficient bounds checking (CWE-606) and results in an infinite loop (CWE-835).
Affected Systems
The vulnerability affects all FreeRDP deployments running any version prior to 3.31.0. The affected product is FreeRDP from the FreeRDP project. No specific sub‑components or modules other than the pool_decode_rect path are listed as affected.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity denial‑of‑service potential. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector is a remote RDP connection: an attacker must be able to act as a server that issues malicious AVC444 updates. The exploit requires no local privileges or code execution; it merely forces the client to hang due to prolonged CPU consumption during graphic decoding.
OpenCVE Enrichment