Impact
The vulnerability is a buffer over-read in the rts_read_result function of the RPC gateway transport parser. An attacker can send a maliciously crafted BIND_ACK Protocol Data Unit with a truncated result entry, causing the process to read beyond allocated memory bounds and abort. This out-of-bounds access can lead to a denial of service by crashing the FreeRDP client process.
Affected Systems
All FreeRDP installations with a version prior to 3.31.0 are affected. The flaw is present inDP product without an explicit patch level or build qualifier. Users should verify if they are running an older release than 3.31.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of < 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a remote network attacker targeting the RPC gateway transport; the attacker must be able to deliver a crafted BIND_ACK PDU to the vulnerable server or client, but no further authentication or privileged access is required. The attack can disrupt service by causing the target application to terminate.
OpenCVE Enrichment