Impact
FreeRDP before version 3.31.0 contains a use‑after RDPDR device handler. When a worker thread fails to start after a device is registered, the device pointer is freed while the device manager still holds a reference, resulting in a crash or potentially allowing arbitrary code execution. This vulnerability is a classic example of CWE-416 and involves an invalid memory reference after deallocation, fitting the description of CWE-825.
Affected Systems
FreeRDP releases older than 3.31.0, specifically any installation that device in those versions, are impacted.
Risk and Exploitability
The CVSS score of 2.3 indicates low overall severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require an attacker to trigger the smartcard channel setup during an RDP session and cause a thread‑creation failure, for which no public exploit exists. Based on the description, the attack vector is inferred to be remote via an RDP connection that initiates a smartcard channel, though precise exploitation conditions are not fully detailed.
OpenCVE Enrichment