An unauthenticated RDP peer can execute code in GNOME Remote Desktop 51 pre-release Remote Login.
GNOME Remote Desktop 51 pre-release Remote Login deployments on Linux distributions embedding FreeRDP 3.28 through 3.30.
A rejected negotiation continues into a disabled security mechanism, after which a heap disclosure supplies addresses for a controlled eight-byte overwrite of a live function-pointer-bearing object.
Detail and 4 sources
Researchers demonstrated pre-authentication execution, but the complete exploit was not published and the scope is limited to GNOME 51 pre-release Remote Login.
FreeRDP published fixes, but their implementation was not assessed for this brief.