Impact
The flaw is an out-of-bounds read in FreeRDP’s URBDRC channel within the func_get_ep_desc function. The code incorrectly indexes interface arrays by position instead of the protocol field InterfaceNumber, allowing an attacker-controlled RDP server to trigger a read past allocated heap memory. Based on the description, it is inferred that the server sends a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to abuse this logic, potentially exposing sensitive memory contents or causing the client to crash.
Affected Systems
All FreeRDP releases before version 3.31.0 are impacted. The vulnerability resides in the URBDRC channel implementation and is present in all builds that compile the default FreeRDP client.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high-severity issue. The EPSS score is reported as < 1%, suggesting a low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker-controlled RDP server to initiate a connection to the vulnerable client and send a specifically crafted SELECT_CONFIGURATION request. Once processed, the client performs an out-of-bounds read that can expose sensitive memory contents or cause the client to terminate, but no active exploit has been publicly documented to date.
OpenCVE Enrichment