Impact
FreeRDP versions before 3.31.0 expose uninitialized heap memory through the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers that cause the client to read uninitialized memory, defeating address space layout randomization. When this information disclosure is chained with other memory corruption bugs, it can lead to remote code execution on the client machine.
Affected Systems
The affected product is the FreeRDP client. All releases from version 2.0.0 up to and including 3.30.0 are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity, and an EPSS score of < 1%; it is not listed in KEV. The attack requires a malicious RDP server that triggers USB transfer failures. The lack of a direct patch or workaround, aside from disabling USB redirection, means the risk remains significant if other exploitation vectors become available.
OpenCVE Enrichment