CyberRota Analysis
AI-GeneratedFreeRDP versions prior to 3.28.0 are vulnerable to a heap-based buffer overflow in the crypto_rsa_common() function, which allows unauthenticated attackers to exploit the flaw by sending specially crafted ciphertexts. This can lead to a denial of service due to the overflow of a fixed 32-byte buffer, potentially allowing attackers to write up to 224 bytes of controlled data. Organizations using affected versions of FreeRDP should prioritize patching this vulnerability to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)