CyberRota Analysis
AI-GeneratedFreeRDP versions prior to 3.30.0 are vulnerable due to a flaw in the kerberos_DecryptMessage function, which improperly handles peer-controlled GSS Wrap-token EC fields, leading to potential out-of-bounds reads and in-place writes. This vulnerability could allow an attacker to exploit the CredSSP/NLA Kerberos decryption process, posing a significant risk to systems utilizing Remote Desktop Protocol. Organizations using FreeRDP should prioritize upgrading to version 3.30.0 or later to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.