CyberRota Analysis
AI-GeneratedFreeRDP versions prior to 3.29.0 are vulnerable to a denial of service attack due to improper validation of maximum PDU body length in the RDPEI server channel handler. An attacker can exploit this flaw by sending a specially crafted header-only RDPEI message, leading to excessive memory allocation on the server and potential service disruption. Organizations using FreeRDP should prioritize patching to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.