A critical heap buffer overflow vulnerability exists in the FreeRDP Windows client, allowing malicious servers to execute arbitrary code on clients upon connection. This flaw affects FreeRDP versions 3.28.0 and older, particularly the unmaintained wfreerdp component. The public disclosure of an exploit significantly increases the risk to users, necessitating immediate updates to version 3.29.0 or later.
The vulnerability arises when a client requests file contents, leading to unchecked data payload sizes that can overwrite memory bounds, thus enabling remote code execution. Organizations are urged to act swiftly to mitigate this risk.