Impact
A heap buffer overflow occurs in the nego_send_negotiation_request function when FreeRDP processes Server Redirection PDU messages that contain attacker‑controlled LoadBalanceInfo fields. The implementation writes an arbitrary‑length field into a fixed 512‑byte buffer without validating the length, which falls under CWE‑120 (unsafe buffers) and CWE‑122 (buffer overflows). The overflow can crash the client, and if the attacker also obtains a memory disclosure they may trigger arbitrary code execution on the target machine.
Affected Systems
FreeRDP clients with versions 2.0.0 through 3.30.0 are impacted. The vulnerability is fixed in release 3.31.0 and later, so any client running a newer version is not affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score of less than 1% signifies that the exploitation probability is currently very low, and the issue is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack requires an attacker who can control an RDP server to send a crafted Server Redirection PDU with an oversized LoadBalanceInfo field, so the likely vector is remote network access to the client. The exploit may cause a denial of service through client crashes and can lead to code execution when combined with a memory disclosure; therefore it warrants immediate attention.
OpenCVE Enrichment