TWO critical vulnerabilities in FreeRDP version 3.31.0 have been identified: an authentication bypass and a remote code execution (RCE) exploit. The patched version addresses five server-role flaws, with potential impacts on various Linux remote desktop tools. The authentication bypass allows unauthorized access by manipulating socket responses. Other issues include memory leaks and a use-after-free bug, mainly leading to denial of service.
Upgrading to version 3.31.0 is highly recommended, while older versions remain at risk, especially for RDP server deployments. Full-chain exposure is currently limited, with no confirmed real-world exploits.