Impact
FreeRDP versions prior to 3.31.0 have a null pointer dereference in the gdi_surface_bits function when handling Surface Bits commands that specify the NSCodec codec. The bug allows a malicious RDP server to send a crafted command that triggers the dereference, causing the client process to crash. The crash denies service to the user and can be repeated, but it does not provide code execution or privilege escalation.
Affected Systems
All installations of FreeRDP that are older than version 3.31.0 are vulnerable regardless of whether NSCodec is enabled. The vulnerability affects the client side of the Remote Desktop Protocol and is mitigated by using a patched release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity moderate risk. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation. FreeRDP clients can be targeted only by an attacker who controls or can impersonate an RDP server, which may require privileged network access or social engineering. Because the vulnerability is triggered by a crafted command, an active attacker with networking access to the client can cause repeated service interruptions. The vulnerability is not listed in the CISA KEV catalog, indicating that no known commercial exploitation campaigns have been observed yet.
OpenCVE Enrichment