Impact
FreeRDP client versions prior to 3.31.0 are vulnerable to an integer overflow in WinPR's Stream_EnsureRemainingCapacity routine. When a remote RD Gateway peer sends a WebSocket Ping frame with a 64-bit extended payload length crafted to wrap the internal counter, the overflow leads to a double free that crashes the client. The crash results in a denial-of-service condition for the user, without compromising data confidentiality or integrity.
Affected Systems
Any installation of the FreeRDP client running a version earlier than 3.31.0. The vulnerability is tied to the client’s WebSocket handling path and affects all platforms supported by the project.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, reflecting moderate‑to‑high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation attempts are currently rare and not widely observed. However, an attacker who can inject traffic into the client via a malicious RD Gateway or otherwise force the client to process a crafted WebSocket Ping frame can trigger the double free, causing a crash and terminating the user session. The risk is therefore primarily denial of service to clients that accept connections from untrusted gateways.
OpenCVE Enrichment