Remote Desktop Protocol Vulnerability in FreeRDP Implementation
CVE-2026-63117
6.5MEDIUM
What is CVE-2026-63117?
A vulnerability exists in the FreeRDP implementation of the Remote Desktop Protocol that allows an authenticated client to exploit specific advertising settings. If the DVI ADPCM settings are manipulated to set nBlockAlign to 8 and nChannels to 2, it causes a critical calculation error in the server-side audio processing. This error, specifically in the bs calculation, results in a division by zero scenario, triggering a SIGFPE signal and leading to an abnormal termination of the rdpsnd channel process on the server. This issue was addressed in version 3.28.0 of FreeRDP.
Affected Version(s)
FreeRDP < 3.28.0
