Impact
FreeRDP fails to validate client‑supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing an attacker to craft RDP packets with zero or oversized dimensions that trigger division‑by‑zero or assertion failures in multifragment update capability calculations. The result is a crash of the server process, producing a denial of service to any client and potentially disrupting all RDP sessions to the server. This vulnerability is classified as CWE-369.
Affected Systems
FreeRDP installations prior to version 3.31.0, i.e., every FreeRDP instance using a server component that accepts remote RDP connections, are vulnerable to a crash when receiving malformed DesktopWidth and DesktopHeight values during GCC negotiation.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity with availability impact. The EPSS score is <1%, the KEV, so the public exploitation likelihood remains unclear. The attack vector is remote through an RDP connection, as the flaw requires an attacker to send modified RDP packets during the initial negotiation. If connected to a public network or an untrusted network, an adversary can trigger the crash by sending crafted packets.
OpenCVE Enrichment