Impact
A heap buffer overflow exists in the nego_send_negotiation_request function of FreeRDP. The vulnerability occurs because the LB_LOAD_BALANCE_INFO field length is not verified prior to copying into a fixed 512-byte buffer. A malicious RDP server or attacker can send a Server Redirection PDU with an oversized field, causing the buffer to overflow and corrupt adjacent heap memory. The resulting overflow can lead to denial of service or heap corruption before the client or server authenticates.
Affected Systems
Any deployment of FreeRDP prior to version 3.31.0 that processes request negotiation is affected. The flaw resides in the FreeRDP client and server implementations and may impact clients or servers that receive Server Redirection PDU, confirming which FreeRDP version they are running to determine if the vulnerability applies.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high severity. EPSS score of < 1% indicates no public evidence of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable remotely via the RDP protocol; an unauthenticated attacker can craft a malicious Server Redirection PDU that triggers the overflow before authentication. If the overflow succeeds it can interrupt service or corrupt heap memory, potentially leading to application instability or further attacks.
OpenCVE Enrichment