Remote Desktop Protocol Vulnerability in FreeRDP Implementation
CVE-2026-63117

6.5MEDIUM

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-63117?

A vulnerability exists in the FreeRDP implementation of the Remote Desktop Protocol that allows an authenticated client to exploit specific advertising settings. If the DVI ADPCM settings are manipulated to set nBlockAlign to 8 and nChannels to 2, it causes a critical calculation error in the server-side audio processing. This error, specifically in the bs calculation, results in a division by zero scenario, triggering a SIGFPE signal and leading to an abnormal termination of the rdpsnd channel process on the server. This issue was addressed in version 3.28.0 of FreeRDP.

Affected Version(s)

FreeRDP < 3.28.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.