Impact
FreeRDP versions before 3.31.0 lack proper bounds validation for MonitorIds array values when parsing RDP connection files, which can lead to unbounded array indexing in the xf_detect_monitors function. This flaw permits attackers to craft a malicious .rdp file containing an out-of-range selectedmonitors value, resulting in an out-of-bounds heap read and write operation during execution of xfreerdp. The vulnerability could potentially corrupt memory, leading to information disclosure or execution of arbitrary code, as it represents a classic out-of-bounds buffer overflow (CWE-125 and CWE-787).
Affected Systems
The issue affects FreeRDP deployments on all platforms running versions 3.11.0 through 3.30.0. Systems that include the xfreerdp client and parse untrusted RDP files are susceptible. Upgrading to 3.31.0 or newer removes the vulnerability.
Risk and Exploitability
The CVSS score of 6.9 combined with an EPSS score of 0.00199 indicates a low but non-zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker providing a crafted .rdp file to a user who then opens it with xfreerdp, possibly enabling an attacker to read or corrupt application memory. The design of the flaw allows local file-based exploitation, so users who handle untrusted RDP files are at the highest risk.
OpenCVE Enrichment