Impact
FreeRDP implements the URBDRC control-transfer protocol. In versions before 3.31.0 the client fails to validate the OutputBufferSize value before forwarding the data to the libusb backend. When a malicious RDP server sends a control-transfer request with OutputBufferSize set to 65536, the client triggers a reachable assertion that terminates the process. The flaw does not allow data disclosure or code execution; it can be used repeatedly to bring the client down, effectively denying service.
Affected Systems
All systems that run the FreeRDP client before release 3.31.0 are affected. This includes any desktop or server environment using the FreeRDP binaries or libraries when connecting to RDP servers, regardless of operating system.
Risk and Exploitability
The CVSS score of 7.1 classifies this vulnerability as moderately severe. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The attack requires an attacker to control the RDP server that the victim connects to; because it is not listed in CISA’s KEV catalog, no widespread exploits are currently documented.
OpenCVE Enrichment